CVE-2015-7808: Input Validation
The vBApiHook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in the arguments parameter to ajax/api/hook/decodeArguments.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7808?
CVE-2015-7808 is considered a critical vulnerability that allows remote attackers to conduct PHP object injection attacks.
How do I fix CVE-2015-7808?
To fix CVE-2015-7808, upgrade to a patched version of vBulletin, specifically versions 5.1.10 or later.
Which versions are affected by CVE-2015-7808?
CVE-2015-7808 affects vBulletin versions 5.1.2 through 5.1.9 and earlier versions.
What types of attacks are possible with CVE-2015-7808?
CVE-2015-7808 allows attackers to execute arbitrary PHP code via a crafted serialized object.
Is CVE-2015-7808 easy to exploit?
Yes, CVE-2015-7808 can be easily exploited if the application is not properly secured against input sanitization.