[CVE-2020-17496] 是 vBulletin 的 ajax/render/widget_php 路由中的一个漏洞,通过向 widgetConfig 参数注入恶意代码实现利用。
受影响系统 vBulletin 5.5.4 ~ 5.6.2
vBulletin 5.x Widget_tabbedcontainer_tab_panel RCE 漏洞测试脚本
用法>
python vBulletin_5.x-tab_panel-RCE.py <dst_ip> <dst_port> (user defined port)
python vBulletin_5.x-tab_panel-RCE.py <dst_ip> (default : 80/tcp)
脚本适用于 Python3(2020.11.07 更新)
仅供对你的系统进行漏洞测试。