HomeSecurityvBulletin: New zero-day affects thousands of forums worldwide!

vBulletin: New zero-day affects thousands of forums worldwide!

A security researcher whose name remains unknown has published details of a zero-day vulnerability in vBulletin, the well-known internet forum software

vBulletin

And it is precisely this publication of the details that poses some risks. The reason? The publication of the vulnerability was made before it had time to be fixed, which means that hacking attacks on forums and interception of user information may be possible.

In fact, the zero-day allows the hacker to execute shell commands on the server. What is noteworthy is that the hacker does not need to have an account on the specific forum.

The publication was made on Full Disclosure. Security researchers often publish details about unpatched security flaws when they have not been patched after repeated reports of the vulnerability. However, until now, it is not clear whether the anonymous security researcher initially reported the vulnerability to the vBulletin team or whether the vBulletin team failed to address the issue in time, leading him to publish it independently. It is not excluded that this is a conscious decision of sabotage, aimed at discrediting vBulletin.

According to W3Techs, 0.1% of sites run a vBulletin forum. That means billions of users are affected. Forums are designed to collect user information . While billions of online sites don’t store information about users, forums can very easily store user data . Therefore, 0.1% is really quite significant when we calculate how many users could be registered in these forums.

While vBulletin is used by many well-known sites, the good news is that the zero-day only affected version 5.x. This effectively means that forums running older versions are safe if they have made the necessary fixes.

vBulletin

Zerodium , a company that buys web-based software to resell to law enforcement agencies. Many dark web forums, such as those that trade criminal services, malware , or child abuse images, often run on vBulletin. According to the company, the anonymous security researcher could have made up to $10,000 in reward money if he had given Zerodium the details of the zero-day and not put that much data at risk by publishing it himself.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS