vBulletin 5.x¶à¸ö¸ßΣÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-10-11Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-17271£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
CVE±àºÅ£ºCVE-2019-17132£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
vBulletin°æ±¾5.0.0µ½×îеÄ5.5.4
Îó²î¸ÅÊö
vBulletinÊÇÃÀ¹úInternet BrandsºÍvBulletin Solutions¹«Ë¾ÅäºÏ¿ª·¢µÄÒ»¿î¿ªÔ´µÄÉÌÒµWebÂÛ̳³ÌÐò¡£¡£¡£
¿ËÈÕ£¬£¬vBulletin ¹Ù·½Ðû²¼ÁËÒ»¸öÈ«ÐÂÇå¾²²¹¶¡£¬£¬¸Ã²¹¶¡ÐÞ¸´ÁËCVE±àºÅΪCVE-2019-17271µÄSQL×¢ÈëÎó²î£¬£¬ÒÔ¼°CVE±àºÅΪCVE-2019-17132µÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£
CVE-2019-17271 SQL×¢ÈëÎó²î
SQL×¢ÈëÎó²îÊÇÁ½¸ö¡°read in-band and time-based¡±µÄSQL×¢ÈëÎÊÌ⣬£¬ËüÃDZ£´æÓÚÁ½¸ö×ÔÁ¦µÄ¶ËµãÉÏ£¬£¬ÔÊÐí¾ßÓÐÊÜÏÞÖÆÌØÈ¨µÄÖÎÀíÔ±´ÓÊý¾Ý¿â¶ÁÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£
£¨1£©Í¨¹ý¡°where¡±²ÎÊýµÄ¼üת´ïµ½¡°ajax/api/hook/getHookList¡±¶ËµãµÄÓû§ÊäÈëÊý¾Ý£¬£¬ÔÚºǫ́¾ÙÐÐSQLÅÌÎÊ֮ǰûÓоÓÉ׼ȷÑéÖ¤Óë¹ýÂË¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÕâÒ»µã£¬£¬Í¨¹ý¡°read in-band¡±SQL×¢Èë¹¥»÷´ÓÊý¾Ý¿âÖжÁÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¿ÉÊÇÀÖ³ÉʹÓôËÎó²îÐèÒªÓû§¾ßÓС°canadminproducts¡±»ò¡°canadminstyles¡±µÄÖÎÀíԱȨÏÞ£¬£¬í§Òâ×¢²áµÄÓû§ÎÞ¸ÃȨÏÞ¡£¡£¡£
£¨2£©Í¨¹ý¡°where¡±²ÎÊýµÄ¼üת´ïµ½¡°ajax/api/widget/getWidgetList¡±¶ËµãµÄÓû§ÊäÈëÊý¾Ý£¬£¬ÔÚºǫ́¾ÙÐÐSQLÅÌÎÊ֮ǰûÓоÓÉ׼ȷÑéÖ¤Óë¹ýÂË¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÕâÒ»µã£¬£¬Í¨¹ý¡°time-based¡±SQL×¢Èë¹¥»÷´ÓÊý¾Ý¿âÖжÁÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¿ÉÊÇÀÖ³ÉʹÓôËÎó²îÐèÒªÓû§¾ßÓС±canusesitebuilder¡±µÄÖÎÀíԱȨÏÞ£¬£¬í§Òâ×¢²áµÄÓû§ÎÞ¸ÃȨÏÞ¡£¡£¡£
CVE-2019-17132 Ô¶³Ì´úÂëÖ´ÐÐÎó²î
vBulletin forum´¦Öóͷ£Óû§¸üÐÂÍ·Ïñ(Óû§µÄСÎÒ˽¼Ò×ÊÁÏ¡¢Í¼±ê»òͼÐÎÌåÏÖ)ÇëÇóʱ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬¸ÃÎó²î±¬·¢µÄÔµ¹ÊÔÓÉÊÇͨ¹ý¡°data[extension]¡±ºÍ¡°data[filedata]¡±²ÎÊýת´ïµ½¡±ajax/api/User/updateAvatar¡±¶ËµãµÄÓû§ÊäÈëÊý¾Ý£¬£¬ÔÚÓÃÓÚ¸üÐÂÓû§µÄavatar֮ǰûÓлñµÃ׼ȷÑéÖ¤¡£¡£¡£Õâ¿ÉÒÔÓÃÀ´×¢ÈëºÍÖ´ÐÐí§ÒâµÄPHP´úÂë¡£¡£¡£¿ÉÊÇÀÖ³ÉʹÓôËÎó²îÐèÒªÖÎÀíÔ±ÆôÓá°ÉúÑÄÍ·ÏñΪÎļþ¡±Ñ¡Ïî(¸ÃÑ¡ÏîĬÈϱ»½ûÓÃ)¡£¡£¡£
ͨ¹ýÍøÂç¿Õ¼äËÑË÷ÒýÇæ¿ÉÒÔµÃÖª£¬£¬ÔÚÈ«Çò¹æÄ£ÄÚ£¬£¬¶Ô»¥ÁªÍø¿ª·ÅµÄvBulletinÍøÕ¾Óнü3Íò¸ö£¬£¬ÆäÖн϶àÍøÕ¾Îª¹ú¼Ê´óÐÍÆóÒµËùά»¤µÄ¹ú¼ÊÉçÇøÂÛ̳£¬£¬ÒÔÊǸÃÎó²îÓ°ÏìÃæ½Ï´ó¡£¡£¡£
Îó²îÑéÖ¤
CVE-2019-17132
POC£ºhttps://packetstormsecurity.com/files/154759/vBulletin-5.5.4-Remote-Code-Execution.html¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º
https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4423646-vbulletin-5-5-x-5-5-2-5-5-3-and-5-5-4-security-patch-level-2¡£¡£¡£
²Î¿¼Á´½Ó
https://packetstormsecurity.com/files/154758/vBulletin-5.5.4-SQL-Injection.html
https://packetstormsecurity.com/files/154759/vBulletin-5.5.4-Remote-Code-Execution.html


¾©¹«Íø°²±¸11010802024551ºÅ