Sploitus

CVE-2019-16759

27 known exploits for CVE-2019-16759

vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.

Affected products
Vbulletin
Vbulletin
≤ 5.5.4
CVSS 3.1
9.8 CRITICAL
EPSS
99.7% (100th percentile)
Weakness
CWE-94
NVD status
Analyzed
Published
2019-09-24
CVE-2019-16759 at NVD
Authoritative description, scoring and affected products

27 known exploits for CVE-2019-16759

Proof-of-concept code and exploit modules indexed by Sploitus

Exploit for Deserialization of Untrusted Data in Redhat Jboss_Enterprise_Application_Platform
2020-12-08 Keepb1ueGITEE
Exploit for Code Injection in Vbulletin
2020-08-31 ludy-devGITHUB
Exploit for Code Injection in Vbulletin
2020-08-24 sunian19GITHUB
Exploit for Code Injection in Vbulletin
2020-08-16 0xdimsGITHUB
Exploit for Code Injection in Vbulletin
2020-08-16 mas1337GITHUB
vBulletin 5.x Remote Code Execution
2020-08-13 ZenofexPACKETSTORMRuby
vBulletin 5.x /ajax/render/widget_tabbedcontainer_tab_panel PHP remote code execution.
2020-08-13 Zenofex <zenofex@exploitee.rs>METASPLOITRuby
vBulletin 5.x Remote Code Execution Exploit
2020-08-12 metasploitZDTRuby
vBulletin 5.6.2 - (widget_tabbedContainer_tab_panel) Remote Code Execution Exploit
2020-08-12 zenofexZDTPython
vBulletin 5.6.2 - 'widget_tabbedContainer_tab_panel' Remote Code Execution
2020-08-12 zenofexEXPLOITDBPython
vBulletin 5.x Remote Code Execution
2020-08-11 ZenofexPACKETSTORMPython
vBulletin 5.x Remote Code Execution
2020-08-11 ZenofexPACKETSTORM
Exploit for Deserialization of Untrusted Data in Redhat Jboss_Enterprise_Application_Platform
2020-05-06 MstirGITEE
Exploit for Code Injection in Vbulletin
2019-12-29 andripwnGITHUB
vBulletin 5.5.4 Remote Command Execution Exploit #RCE
2019-12-11 metasploitZDTRuby
vBulletin 5.5.4 Remote Command Execution
2019-12-10 mekhallehPACKETSTORMRuby
vBulletin widgetConfig RCE
2019-10-18 unknown, mekhalleh (RAMELLA Sébastien)METASPLOITRuby
Exploit for Code Injection in Vbulletin
2019-10-12 FarjaalAhmadGITHUB
vBulletin 5.x - Remote Command Execution Exploit
2019-10-01 r00tpgpZDTRuby
vBulletin 5.x - Remote Command Execution (Metasploit)
2019-09-30 r00tpgpEXPLOITPACKRuby
vBulletin 5.x - Remote Command Execution (Metasploit)
2019-09-30 r00tpgpEXPLOITDBRuby
vBulletin 5.x Pre-Auth Remote Code Execution
2019-09-28 r00tpgpPACKETSTORMRuby
vBulletin 5.x 0-Day Pre-Auth Remote Command Execution
2019-09-26 r00tpgpPACKETSTORM
Exploit for Code Injection in Vbulletin
2019-09-26 r00tpgpGITHUB
Exploit for Code Injection in Vbulletin
2019-09-26 jas502nGITHUB
Immunity Canvas: VBULLETIN_WIDGET_RCE
2019-09-24 Immunity CanvasCANVAS
vBulletin 5.0 < 5.5.4 - 'widget_php ' Unauthenticated Remote Code Execution
2019-09-23 anonymousEXPLOITDBPython