vBulletin 'getIndexableContent' SQL Injection (direct check)

critical Nessus Plugin ID 136613

Synopsis

A bulletin board system running on the remote web server has an SQL injection vulnerability.

Description

The version of vBulletin running on the remote host is affected by an input-validation flaw in the content_infraction/getIndexableContent API that allows for SQL injection. This can be levereged by an attacker to obtain administrator privileges leading to remote code execution.

Solution

Upgrade to vBulletin 5.6.1 PL1 or 5.6.0 PL1 or 5.5.6 PL1 or later.

See Also

http://www.nessus.org/u?185c2276

http://www.nessus.org/u?396e8bf9

https://twitter.com/Zenofex/status/1260164977077424128

Plugin Details

Severity: Critical

ID: 136613

File Name: vbulletin_CVE-2020-12720_direct.nasl

Version: 1.7

Type: remote

Family: CGI abuses

Published: 5/15/2020

Updated: 12/5/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.2

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2020-12720

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:vbulletin:vbulletin

Required KB Items: www/vBulletin

Exploit Available: true

Exploit Ease: Exploits are available

Exploited by Nessus: true

Patch Publication Date: 5/7/2020

Vulnerability Publication Date: 5/7/2020

Exploitable With

Metasploit (vBulletin /ajax/api/content_infraction/getIndexableContent nodeid Parameter SQL Injection)

Elliot (vBulletin 5 SQL Injection)

Reference Information

CVE: CVE-2020-12720