Sploitus

Exploit for Code Injection in Vbulletin CVE-2019-16759

githubexploit · 2020-08-31

Exploit Code

README20 lines
## https://sploitus.com/exploit?id=E827264A-33DB-5591-9107-3B2C883318B9
# [CVE-2019-16759]vBulletin_Routestring-RCE-PoC
A vulnerability has been discovered in vBulletin which could allow for remote code execution when a malicious POST request is sent to the vulnerable application. 
The vulnerability is due to an input validation error while parsing a HTTP request in the vulnerable module. 

System Affected : 

vBulletin Version 5.0.0 ~ 5.5.4 
(Updated System affected) vBulletin Version 5.0.0 ~ 5.6.2

Usage>

    python vBulletin_Routestring-RCE.py   (User defined port) 

    python vBulletin_Routestring-RCE.py  (default Port:80)   

Script was editted for Python3 


Not For attack. just using Vuln Test for your System