vBulletin.Administrator.Account.Authentication.Bypass
Description
This indicates an attack attempt to exploit an Authentication Bypass vulnerability in vBulletin.
The vulnerability is due to a validation error in the application when handling an HTTP request. Via an HTTP request, an unauthenticated remote attacker may be able to exploit this to bypass authentication on vulnerable systems by adding administrative accounts.
Affected Products
vBulletin 4.1
vBulletin 5.0.0
Impact
Security Bypass: Remote attackers can bypass security features of vulnerable systems by adding administrative accounts without authentication.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://www.vbulletin.com/forum/forum/vbulletin-announcements/vbulletin-announcements_aa/3991423-vbulletin-install-system-exploit-vbulletin-4-1-vbulletin-5
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |