CVE-2019-16759
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
- Affected products
- Vbulletin
- Vbulletin
- ≤ 5.5.4
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 99.7% (100th percentile)
- Weakness
- CWE-94
- NVD status
- Analyzed
- Published
- 2019-09-24
CVE-2019-16759 at NVD
27 known exploits for CVE-2019-16759
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Deserialization of Untrusted Data in Redhat Jboss_Enterprise_Application_Platform
Exploit for Code Injection in Vbulletin
Exploit for Code Injection in Vbulletin
Exploit for Code Injection in Vbulletin
Exploit for Code Injection in Vbulletin
vBulletin 5.x Remote Code Execution
vBulletin 5.x /ajax/render/widget_tabbedcontainer_tab_panel PHP remote code execution.
vBulletin 5.x Remote Code Execution Exploit
vBulletin 5.6.2 - (widget_tabbedContainer_tab_panel) Remote Code Execution Exploit
vBulletin 5.6.2 - 'widget_tabbedContainer_tab_panel' Remote Code Execution
vBulletin 5.x Remote Code Execution
vBulletin 5.x Remote Code Execution
Exploit for Deserialization of Untrusted Data in Redhat Jboss_Enterprise_Application_Platform
Exploit for Code Injection in Vbulletin
vBulletin 5.5.4 Remote Command Execution Exploit #RCE
vBulletin 5.5.4 Remote Command Execution
vBulletin widgetConfig RCE
Exploit for Code Injection in Vbulletin
vBulletin 5.x - Remote Command Execution Exploit
vBulletin 5.x - Remote Command Execution (Metasploit)
vBulletin 5.x - Remote Command Execution (Metasploit)
vBulletin 5.x Pre-Auth Remote Code Execution
vBulletin 5.x 0-Day Pre-Auth Remote Command Execution
Exploit for Code Injection in Vbulletin
Exploit for Code Injection in Vbulletin
Immunity Canvas: VBULLETIN_WIDGET_RCE
vBulletin 5.0 < 5.5.4 - 'widget_php ' Unauthenticated Remote Code Execution