vBulletin 5.x¶à¸ö¸ßΣ·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-10-11·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-17271£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-17132£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
vBulletin°æ±¾5.0.0µ½×îеÄ5.5.4
·ì϶¸ÅÊö
vBulletinÊÇÃÀ¹úInternet BrandsºÍvBulletin Solutions¹«Ë¾¹²Í¬¿ª·¢µÄÒ»¿î¿ªÔ´µÄóÒ×WebÂÛ̳·¨Ê½¡£¡£¡£¡£¡£¡£¡£
½üÈÕ£¬£¬£¬£¬£¬vBulletin ¹Ù·½°ä²¼ÁËÒ»¸öȫа²È«²¹¶¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬¸Ã²¹¶¡½¨¸´ÁËCVE±àºÅΪCVE-2019-17271µÄSQL×¢Èë·ì϶£¬£¬£¬£¬£¬ÒÔ¼°CVE±àºÅΪCVE-2019-17132µÄÔ¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£¡£
CVE-2019-17271 SQL×¢Èë·ì϶
SQL×¢Èë·ì϶ÊÇÁ½¸ö¡°read in-band and time-based¡±µÄSQL×¢ÈëÎÊÌ⣬£¬£¬£¬£¬ËüÃÇ´æÔÚÓÚÁ½¸ö¶ÀÁ¢µÄ¶ËµãÉÏ£¬£¬£¬£¬£¬ÔÊÐíÓµÓÐÊÜÏÞ¶ÈÌØÈ¨µÄÖÎÀíÔ±´ÓÊý¾Ý¿â¶ÁÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£
£¨1£©Í¨¹ý¡°where¡±²ÎÊýµÄ¼ü´«µÝµ½¡°ajax/api/hook/getHookList¡±¶ËµãµÄÓû§ÊäÈëÊý¾Ý£¬£¬£¬£¬£¬ÔÚºó¶Ü½øÐÐSQL²éÎÊ֮ǰûÓо¹ýÕýÈ·ÑéÖ¤Óë¹ýÂË¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷ÕßÄܹ»ÀûÓÃÕâÒ»µã£¬£¬£¬£¬£¬Í¨¹ý¡°read in-band¡±SQL×¢Èë¹¥»÷´ÓÊý¾Ý¿âÖжÁÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£µ«Êdzɹ¦ÀûÓô˷ì϶±ØÒªÓû§¾ßÓÓ×°canadminproducts¡±»ò¡°canadminstyles¡±µÄÖÎÀíԱȨÏÞ£¬£¬£¬£¬£¬ËÁÒâ×¢²áµÄÓû§ÎÞ¸ÃȨÏÞ¡£¡£¡£¡£¡£¡£¡£
£¨2£©Í¨¹ý¡°where¡±²ÎÊýµÄ¼ü´«µÝµ½¡°ajax/api/widget/getWidgetList¡±¶ËµãµÄÓû§ÊäÈëÊý¾Ý£¬£¬£¬£¬£¬ÔÚºó¶Ü½øÐÐSQL²éÎÊ֮ǰûÓо¹ýÕýÈ·ÑéÖ¤Óë¹ýÂË¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷ÕßÄܹ»ÀûÓÃÕâÒ»µã£¬£¬£¬£¬£¬Í¨¹ý¡°time-based¡±SQL×¢Èë¹¥»÷´ÓÊý¾Ý¿âÖжÁÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£µ«Êdzɹ¦ÀûÓô˷ì϶±ØÒªÓû§¾ßÓÓ×±canusesitebuilder¡±µÄÖÎÀíԱȨÏÞ£¬£¬£¬£¬£¬ËÁÒâ×¢²áµÄÓû§ÎÞ¸ÃȨÏÞ¡£¡£¡£¡£¡£¡£¡£
CVE-2019-17132 Ô¶³Ì´úÂëÖ´Ðзì϶
vBulletin forum´¦ÖÃÓû§¸üÐÂÍ·Ïñ(Óû§µÄÓ×ÎÒ×ÊÁÏ¡¢Í¼±ê»òͼÐΰµÊ¾)ÒªÇóʱ´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬¸Ã·ì϶²úÉúµÄÔÒòÊÇͨ¹ý¡°data[extension]¡±ºÍ¡°data[filedata]¡±²ÎÊý´«µÝµ½¡±ajax/api/User/updateAvatar¡±¶ËµãµÄÓû§ÊäÈëÊý¾Ý£¬£¬£¬£¬£¬ÔÚÓÃÓÚ¸üÐÂÓû§µÄavatar֮ǰûÓеõ½ÕýÈ·ÑéÖ¤¡£¡£¡£¡£¡£¡£¡£ÕâÄܹ»ÓÃÀ´×¢ÈëºÍÖ´ÐÐËÁÒâµÄPHP´úÂë¡£¡£¡£¡£¡£¡£¡£µ«Êdzɹ¦ÀûÓô˷ì϶±ØÒªÖÎÀíÔ±ÆôÓá°±£ÁôÍ·ÏñΪÎļþ¡±Ñ¡Ïî(¸ÃÑ¡ÏîĬÈϱ»½ûÓÃ)¡£¡£¡£¡£¡£¡£¡£
ͨ¹ýÍøÂç¿Õ¼äËÑË÷ÒýÇæÄܹ»µÃÖª£¬£¬£¬£¬£¬ÔÚÈ«ÇòÁìÓòÄÚ£¬£¬£¬£¬£¬¶Ô»¥ÁªÍøÊ¢¿ªµÄvBulletinÍøÕ¾Óнü3Íò¸ö£¬£¬£¬£¬£¬ÆäÖн϶àÍøÕ¾Îª¹ú¼Ê´óÐÍÆóÒµËùÊØ»¤µÄ¹ú¼ÊÉçÇøÂÛ̳£¬£¬£¬£¬£¬ËùÒԸ÷ì϶ӰÏìÃæ½Ï´ó¡£¡£¡£¡£¡£¡£¡£
·ì϶ÑéÖ¤
CVE-2019-17132
POC£ºhttps://packetstormsecurity.com/files/154759/vBulletin-5.5.4-Remote-Code-Execution.html¡£¡£¡£¡£¡£¡£¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º
https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4423646-vbulletin-5-5-x-5-5-2-5-5-3-and-5-5-4-security-patch-level-2¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://packetstormsecurity.com/files/154758/vBulletin-5.5.4-SQL-Injection.html
https://packetstormsecurity.com/files/154759/vBulletin-5.5.4-Remote-Code-Execution.html


¾©¹«Íø°²±¸11010802024551ºÅ