vBulletin 5.x¶à¸ö¸ßΣÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-10-11

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-17271£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-17132£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


vBulletin°æ±¾5.0.0µ½×îеÄ5.5.4


Îó²î¸ÅÊö


vBulletinÊÇÃÀ¹úInternet BrandsºÍvBulletin Solutions¹«Ë¾ÅäºÏ¿ª·¢µÄÒ»¿î¿ªÔ´µÄÉÌÒµWebÂÛ̳³ÌÐò¡£¡£¡£


¿ËÈÕ£¬£¬£¬vBulletin ¹Ù·½Ðû²¼ÁËÒ»¸öÈ«ÐÂÇå¾²²¹¶¡£¡£¡£¬£¬£¬¸Ã²¹¶¡ÐÞ¸´ÁËCVE±àºÅΪCVE-2019-17271µÄSQL×¢ÈëÎó²î£¬£¬£¬ÒÔ¼°CVE±àºÅΪCVE-2019-17132µÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£


CVE-2019-17271 SQL×¢ÈëÎó²î


SQL×¢ÈëÎó²îÊÇÁ½¸ö¡°read in-band and time-based¡±µÄSQL×¢ÈëÎÊÌ⣬£¬£¬ËüÃDZ£´æÓÚÁ½¸ö×ÔÁ¦µÄ¶ËµãÉÏ£¬£¬£¬ÔÊÐí¾ßÓÐÊÜÏÞÖÆÌØÈ¨µÄÖÎÀíÔ±´ÓÊý¾Ý¿â¶ÁÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£


£¨1£©Í¨¹ý¡°where¡±²ÎÊýµÄ¼üת´ïµ½¡°ajax/api/hook/getHookList¡±¶ËµãµÄÓû§ÊäÈëÊý¾Ý£¬£¬£¬ÔÚºǫ́¾ÙÐÐSQLÅÌÎÊ֮ǰûÓо­ÓÉ׼ȷÑéÖ¤Óë¹ýÂË¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÕâÒ»µã£¬£¬£¬Í¨¹ý¡°read in-band¡±SQL×¢Èë¹¥»÷´ÓÊý¾Ý¿âÖжÁÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¿ÉÊÇÀÖ³ÉʹÓôËÎó²îÐèÒªÓû§¾ßÓС°canadminproducts¡±»ò¡°canadminstyles¡±µÄÖÎÀíԱȨÏÞ£¬£¬£¬í§Òâ×¢²áµÄÓû§ÎÞ¸ÃȨÏÞ¡£¡£¡£


£¨2£©Í¨¹ý¡°where¡±²ÎÊýµÄ¼üת´ïµ½¡°ajax/api/widget/getWidgetList¡±¶ËµãµÄÓû§ÊäÈëÊý¾Ý£¬£¬£¬ÔÚºǫ́¾ÙÐÐSQLÅÌÎÊ֮ǰûÓо­ÓÉ׼ȷÑéÖ¤Óë¹ýÂË¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÕâÒ»µã£¬£¬£¬Í¨¹ý¡°time-based¡±SQL×¢Èë¹¥»÷´ÓÊý¾Ý¿âÖжÁÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¿ÉÊÇÀÖ³ÉʹÓôËÎó²îÐèÒªÓû§¾ßÓС±canusesitebuilder¡±µÄÖÎÀíԱȨÏÞ£¬£¬£¬í§Òâ×¢²áµÄÓû§ÎÞ¸ÃȨÏÞ¡£¡£¡£


CVE-2019-17132 Ô¶³Ì´úÂëÖ´ÐÐÎó²î


vBulletin forum´¦Öóͷ£Óû§¸üÐÂÍ·Ïñ(Óû§µÄСÎÒ˽¼Ò×ÊÁÏ¡¢Í¼±ê»òͼÐÎÌåÏÖ)ÇëÇóʱ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬¸ÃÎó²î±¬·¢µÄÔµ¹ÊÔ­ÓÉÊÇͨ¹ý¡°data[extension]¡±ºÍ¡°data[filedata]¡±²ÎÊýת´ïµ½¡±ajax/api/User/updateAvatar¡±¶ËµãµÄÓû§ÊäÈëÊý¾Ý£¬£¬£¬ÔÚÓÃÓÚ¸üÐÂÓû§µÄavatar֮ǰûÓлñµÃ׼ȷÑéÖ¤¡£¡£¡£Õâ¿ÉÒÔÓÃÀ´×¢ÈëºÍÖ´ÐÐí§ÒâµÄPHP´úÂë¡£¡£¡£¿ÉÊÇÀÖ³ÉʹÓôËÎó²îÐèÒªÖÎÀíÔ±ÆôÓá°ÉúÑÄÍ·ÏñΪÎļþ¡±Ñ¡Ïî(¸ÃÑ¡ÏîĬÈϱ»½ûÓÃ)¡£¡£¡£


ͨ¹ýÍøÂç¿Õ¼äËÑË÷ÒýÇæ¿ÉÒÔµÃÖª£¬£¬£¬ÔÚÈ«Çò¹æÄ£ÄÚ£¬£¬£¬¶Ô»¥ÁªÍø¿ª·ÅµÄvBulletinÍøÕ¾Óнü3Íò¸ö£¬£¬£¬ÆäÖн϶àÍøÕ¾Îª¹ú¼Ê´óÐÍÆóÒµËùά»¤µÄ¹ú¼ÊÉçÇøÂÛ̳£¬£¬£¬ÒÔÊǸÃÎó²îÓ°ÏìÃæ½Ï´ó¡£¡£¡£


Îó²îÑéÖ¤


CVE-2019-17132

POC£ºhttps://packetstormsecurity.com/files/154759/vBulletin-5.5.4-Remote-Code-Execution.html¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º

https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4423646-vbulletin-5-5-x-5-5-2-5-5-3-and-5-5-4-security-patch-level-2¡£¡£¡£


²Î¿¼Á´½Ó


https://packetstormsecurity.com/files/154758/vBulletin-5.5.4-SQL-Injection.html

https://packetstormsecurity.com/files/154759/vBulletin-5.5.4-Remote-Code-Execution.html