CVE-2013-6129: High severity vBulletin vBulletin vulnerability
The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid, htmldata[password], htmldata[confirmpassword], and htmldata[email] parameters, as exploited in the wild in October 2013.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
vBulletin install/upgrade.phpto a version that resolves this vulnerability.Fixed in 4.1 - Upgrade
Upgrade
vBulletin install/upgrade.phpto a version that resolves this vulnerability.Fixed in 5
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6129?
CVE-2013-6129 has a critical severity rating allowing attackers to create administrative accounts.
How do I fix CVE-2013-6129?
To fix CVE-2013-6129, update your vBulletin to the latest available version that addresses this vulnerability.
Which versions of vBulletin are affected by CVE-2013-6129?
CVE-2013-6129 affects vBulletin versions 4.1 and 5.0.0.
Can CVE-2013-6129 be exploited remotely?
Yes, CVE-2013-6129 can be exploited remotely by attackers to gain unauthorized access.
What parameters are involved in the exploitation of CVE-2013-6129?
The parameters involved in the exploitation of CVE-2013-6129 include customerid, htmldata[password], htmldata[confirmpassword], and htmldata[email].