In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circumstances, code execution, because of unsafe usage of PHP's unserialize() in vB_Library_Template's cacheTemplates() function, which is a publicly exposed API. This is exploited with the templateidlist parameter to ajax/api/template/cacheTemplates.
References
Link Resource
https://blogs.securiteam.com/index.php/archives/3573 Exploit Third Party Advisory
https://www.exploit-db.com/exploits/43362/ Exploit Third Party Advisory VDB Entry
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2017-12-14T00:00:00

Updated: 2017-12-19T10:57:01

Reserved: 2017-12-13T00:00:00


Link: CVE-2017-17672

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2017-12-14T00:29:00.263

Modified: 2018-01-02T16:29:16.963


Link: CVE-2017-17672

JSON object: View

cve-icon Redhat Information

No data.

CWE