In vBulletin before 5.3.0, remote attackers can bypass the CVE-2016-6483 patch and conduct SSRF attacks by leveraging the behavior of the PHP parse_url function, aka VBV-17037.
References
Link | Resource |
---|---|
https://www.vbulletin.com/forum/forum/vbulletin-announcements/vbulletin-announcements_aa/4367744-vbulletin-5-3-0-connect-is-now-available | Release Notes Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2022-10-03T16:23:00
Updated: 2022-10-03T16:23:00
Reserved: 2022-10-03T00:00:00
Link: CVE-2017-7569
JSON object: View
NVD Information
Status : Analyzed
Published: 2017-04-06T17:59:00.193
Modified: 2017-04-12T20:46:58.417
Link: CVE-2017-7569
JSON object: View
Redhat Information
No data.
CWE