vBulletin 5.x¶à¸ö¸ßΣ·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-10-11

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-17271 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-17132 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


vBulletin°æ±¾5.0.0µ½×îеÄ5.5.4


·ì϶¸ÅÊö


vBulletinÊÇÃÀ¹úInternet BrandsºÍvBulletin Solutions¹«Ë¾¹²Í¬¿ª·¢µÄÒ»¿î¿ªÔ´µÄóÒ×WebÂÛ̳·¨Ê½ ¡£


½üÈÕ £¬vBulletin ¹Ù·½°ä²¼ÁËÒ»¸öȫа²È«²¹¶¡ £¬¸Ã²¹¶¡½¨¸´ÁËCVE±àºÅΪCVE-2019-17271µÄSQL×¢Èë·ì϶ £¬ÒÔ¼°CVE±àºÅΪCVE-2019-17132µÄÔ¶³Ì´úÂëÖ´Ðзì϶ ¡£


CVE-2019-17271 SQL×¢Èë·ì϶


SQL×¢Èë·ì϶ÊÇÁ½¸ö¡°read in-band and time-based¡±µÄSQL×¢ÈëÎÊÌâ £¬ËüÃÇ´æÔÚÓÚÁ½¸ö¶ÀÁ¢µÄ¶ËµãÉÏ £¬ÔÊÐíÓµÓÐÊÜÏÞ¶ÈÌØÈ¨µÄÖÎÀíÔ±´ÓÊý¾Ý¿â¶ÁÈ¡Ãô¸ÐÊý¾Ý ¡£


£¨1£©Í¨¹ý¡°where¡±²ÎÊýµÄ¼ü´«µÝµ½¡°ajax/api/hook/getHookList¡±¶ËµãµÄÓû§ÊäÈëÊý¾Ý £¬ÔÚºó¶Ü½øÐÐSQL²éÎÊ֮ǰûÓо­¹ýÕýÈ·ÑéÖ¤Óë¹ýÂË ¡£Ô¶³Ì¹¥»÷ÕßÄܹ»ÀûÓÃÕâÒ»µã £¬Í¨¹ý¡°read in-band¡±SQL×¢Èë¹¥»÷´ÓÊý¾Ý¿âÖжÁÈ¡Ãô¸ÐÊý¾Ý ¡£µ«Êdzɹ¦ÀûÓô˷ì϶±ØÒªÓû§¾ßÓÓ×°canadminproducts¡±»ò¡°canadminstyles¡±µÄÖÎÀíԱȨÏÞ £¬ËÁÒâ×¢²áµÄÓû§ÎÞ¸ÃȨÏÞ ¡£


£¨2£©Í¨¹ý¡°where¡±²ÎÊýµÄ¼ü´«µÝµ½¡°ajax/api/widget/getWidgetList¡±¶ËµãµÄÓû§ÊäÈëÊý¾Ý £¬ÔÚºó¶Ü½øÐÐSQL²éÎÊ֮ǰûÓо­¹ýÕýÈ·ÑéÖ¤Óë¹ýÂË ¡£Ô¶³Ì¹¥»÷ÕßÄܹ»ÀûÓÃÕâÒ»µã £¬Í¨¹ý¡°time-based¡±SQL×¢Èë¹¥»÷´ÓÊý¾Ý¿âÖжÁÈ¡Ãô¸ÐÊý¾Ý ¡£µ«Êdzɹ¦ÀûÓô˷ì϶±ØÒªÓû§¾ßÓÓ×±canusesitebuilder¡±µÄÖÎÀíԱȨÏÞ £¬ËÁÒâ×¢²áµÄÓû§ÎÞ¸ÃȨÏÞ ¡£


CVE-2019-17132 Ô¶³Ì´úÂëÖ´Ðзì϶


vBulletin forum´¦ÖÃÓû§¸üÐÂÍ·Ïñ(Óû§µÄÓ×ÎÒ×ÊÁÏ¡¢Í¼±ê»òͼÐΰµÊ¾)ÒªÇóʱ´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶ £¬¸Ã·ì϶²úÉúµÄÔ­ÒòÊÇͨ¹ý¡°data[extension]¡±ºÍ¡°data[filedata]¡±²ÎÊý´«µÝµ½¡±ajax/api/User/updateAvatar¡±¶ËµãµÄÓû§ÊäÈëÊý¾Ý £¬ÔÚÓÃÓÚ¸üÐÂÓû§µÄavatar֮ǰûÓеõ½ÕýÈ·ÑéÖ¤ ¡£ÕâÄܹ»ÓÃÀ´×¢ÈëºÍÖ´ÐÐËÁÒâµÄPHP´úÂë ¡£µ«Êdzɹ¦ÀûÓô˷ì϶±ØÒªÖÎÀíÔ±ÆôÓá°±£ÁôÍ·ÏñΪÎļþ¡±Ñ¡Ïî(¸ÃÑ¡ÏîĬÈϱ»½ûÓÃ) ¡£


ͨ¹ýÍøÂç¿Õ¼äËÑË÷ÒýÇæÄܹ»µÃÖª £¬ÔÚÈ«ÇòÁìÓòÄÚ £¬¶Ô»¥ÁªÍøÊ¢¿ªµÄvBulletinÍøÕ¾Óнü3Íò¸ö £¬ÆäÖн϶àÍøÕ¾Îª¹ú¼Ê´óÐÍÆóÒµËùÊØ»¤µÄ¹ú¼ÊÉçÇøÂÛ̳ £¬ËùÒԸ÷ì϶ӰÏìÃæ½Ï´ó ¡£


·ì϶ÑéÖ¤


CVE-2019-17132

POC£ºhttps://packetstormsecurity.com/files/154759/vBulletin-5.5.4-Remote-Code-Execution.html ¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶ £¬²¹¶¡»ñÈ¡Á´½Ó£º

https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4423646-vbulletin-5-5-x-5-5-2-5-5-3-and-5-5-4-security-patch-level-2 ¡£


²Î¿¼Á´½Ó


https://packetstormsecurity.com/files/154758/vBulletin-5.5.4-SQL-Injection.html

https://packetstormsecurity.com/files/154759/vBulletin-5.5.4-Remote-Code-Execution.html