CVE-2016-6195: SQL Injection
SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 allows remote attackers to execute arbitrary SQL commands via the postids parameter to forumrunner/request.php, as exploited in the wild in July 2016.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6195?
CVE-2016-6195 is classified as a critical SQL injection vulnerability that can result in remote code execution.
How do I fix CVE-2016-6195?
To fix CVE-2016-6195, update your vBulletin installation to version 4.2.2 Patch Level 5 or 4.2.3 Patch Level 1 or later.
What are the affected versions for CVE-2016-6195?
CVE-2016-6195 affects vBulletin versions prior to 4.2.2 Patch Level 5 and version 4.2.3 before Patch Level 1.
Can CVE-2016-6195 lead to data loss?
Yes, CVE-2016-6195 can allow attackers to execute arbitrary SQL commands, potentially leading to data loss or corruption.
How can I check if my system is vulnerable to CVE-2016-6195?
You can check if your system is vulnerable by confirming the vBulletin version and patches implemented against CVE-2016-6195.