CVE-2015-7808
HIGH 7.5EPSS 80.6%
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in the arguments parameter to ajax/api/hook/decodeArguments.
- CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 80.64% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2015-11-24
- Updated
- 2024-08-06
Proof-of-concept exploits (4)
- http://www.rapid7.com/db/modules/exploit/multi/http/vbulletin_unserialize
- PleXone2019/vBulletin-5.1.x-PreAuth-RCE0★ · 2020-01-29
- Prajithp/CVE-2015-78081★ · 2015-11-06
- mukarramkhalid/vBulletin-5.1.x-PreAuth-RCE20★ · 2021-08-27
Metasploit modules (1)
ExploitDB entries (3)
- https://www.exploit-db.com/exploits/38790
- https://www.exploit-db.com/exploits/38629
- https://www.exploit-db.com/exploits/48761