Add CVE-2019-16759

This commit is contained in:
tardc 2020-04-28 13:35:59 +08:00
parent 2ec50146b0
commit e5729add18
2 changed files with 11 additions and 0 deletions

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.0 MiB

View File

@ -0,0 +1,11 @@
# CVE-2019-16759 vBulletin 5.x Remote Code Execution Vulnerability
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
**Affected version**: vBulletin 5.x - 5.5.4
**[FOFA](https://fofa.so/result?qbase64=YXBwPSJ2QnVsbGV0aW4i) query rule**: app="vBulletin"
# Demo
![](CVE-2019-16759.gif)