News

Zero Day in Less Than 20 Lines of Python Code

Giulio Saggin
Giulio Saggin
Tuesday 28 November 2023

An unpatched zero day with the potential to affect tens of millions of forum users has been published by an anonymous security researcher.

The flaw, which was found in the internet forum software vBulletin, was published on the Full Disclosure mailing list. It shows how a HTTP POST request can be used by a hacker to remotely execute commands on a vBulletin server, even if the hacker doesn't have an account on the targeted forum. And it can all be achieved in less than 20 lines of Python code.

vBulletin is run on .1% of all internet sites, which may not seem like much. However, there are over 1.5 billion websites, so .1% accounts for around 1.5 million.

The fact that forums are involved, many of which have registered members who have handed over personal data, means that millions - tens of millions, even - of users could be at risk, across some prominent websites using vBulletin that include NASA, the Denver Broncos, Sony Pictures, Fitday, Zynga and the Houston Texans.

The circumstances surrounding the zero day being published are unclear (vBulletin and the anonymous researcher have not spoken) and it's not known if the researcher reported the flaw to vBulletin, or if the vBulletin were alerted and didn't fix the issue in a time frame to the researcher's liking.

The zero-day works against vBulletin versions 5.0.0 to 5.5.4 and, at the time of writing, a fix is yet to be found. Forums using earlier versions are okay, so long as they have updated their security patches.

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203