
(CVE-2020-17496) Script di test della vulnerabilità RCE di Widget_tabbedcontainer_tab_panel in vBulletin 5.x
[CVE-2020-17496] è una vulnerabilità nella route ajax/render/widget_php di vBulletin ottenuta tramite l'iniezione di codice malevolo nel parametro widgetConfig.
Sistema interessato vBulletin 5.5.4 ~ 5.6.2
Script di test della vulnerabilità RCE di vBulletin 5.x Widget_tabbedcontainer_tab_panel
Utilizzo>
python vBulletin_5.x-tab_panel-RCE.py <dst_ip> <dst_port> (user defined port)
python vBulletin_5.x-tab_panel-RCE.py <dst_ip> (default : 80/tcp)
Lo script funziona su Python3 (aggiornato il 2020.11.07)
Utilizza questo script solo per testare la vulnerabilità del tuo sistema.