Dangerous VBulletin Exploit In the Wild 43
An anonymous reader writes "vBulletin is a popular proprietary CMS that was recently reported to be vulnerable to an unspecified attack vector. Although vBulletin has not disclosed the root cause of the vulnerability or its impact, we determined the attacker's methods. The identified vulnerability allows an attacker to abuse the vBulletin configuration mechanism in order to create a secondary administrative account. Once the attacker creates the account, they will have full control over the exploited vBulletin application, and subsequently the supported site."
Short form: (Score:5, Informative)
For the TL;DR crowd:
* Delete /core/install and /install directory in all 4.x and 5.x vBulletin installs or block access to same. Do it now.
Min
CMS? (Score:3, Informative)
Did vBulletin change or something. I thought vBulletin was forum software, this states CMS. Or is CMS the preferred buzzword du jour?
Either way, this will mean more spam on lots of forums and more identity theft for those that use the same password for forums and bank accounts. Yawn.
Re:CMS? (Score:4, Informative)
vBulletin added a CMS and blog component in a previous major rewrite.