vBulletin 'faq.php' Information Disclosure Vulnerability
BID:41875
Info
vBulletin 'faq.php' Information Disclosure Vulnerability
| Bugtraq ID: | 41875 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 21 2010 12:00AM |
| Updated: | Jul 22 2010 09:26PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
VBulletin VBulletin 3.8.6 |
| Not Vulnerable: | |
Discussion
vBulletin 'faq.php' Information Disclosure Vulnerability
vBulletin is prone to an information-disclosure vulnerability.
Successful exploits can allow attackers to obtain potentially sensitive information which may aid in other attacks.
vBulletin 3.8.6 is affected; prior versions may also be vulnerable.
vBulletin is prone to an information-disclosure vulnerability.
Successful exploits can allow attackers to obtain potentially sensitive information which may aid in other attacks.
vBulletin 3.8.6 is affected; prior versions may also be vulnerable.
Exploit / POC
vBulletin 'faq.php' Information Disclosure Vulnerability
An attacker can exploit this issue via a browser.
An attacker can exploit this issue via a browser.
Solution / Fix
vBulletin 'faq.php' Information Disclosure Vulnerability
Solution:
The vendor has released a patch to address this issue. Please see the references for more information.
Solution:
The vendor has released a patch to address this issue. Please see the references for more information.
References
vBulletin 'faq.php' Information Disclosure Vulnerability
References:
References:
- Security Patch Release 3.8.6 PL1 (vBulletin)
- vBulletin Homepage (vBulletin)
- vBulletin - Critical Information Disclosure ([email protected])