vBulletin vB 3.8.6 vulnerability
Last Updated: 2010-07-23 15:43:21 UTC
by Mark Hofman (Version: 1)
When teaching Security Essentials (sec401) we often talk about one of the more useful hacking tools in everyone's arsenal, a browser. Wielding a browser in the right manner can expose all kinds of interesting information as is the case with vBulletin version 3.8.6.
vBulletin, used to power online discussion sites has a serious flaw in vB 3.8.6. Browsing to the FAQ page on a vulnerable site and searching for the correct term will disclose the database credentials which can then be used to further compromise the site (http://www.securityfocus.com/archive/1/512575). It shows that vulnerabilities do not need to be complex. It also shows that code review, testing and of course input validation is essential.
The vendor jumped on the issue quickly and provides a patch on their site. Later versions of the product that are not vulnerable are also available. There do still seem to be sites up running the vulnerable code. If yours is one of those, you may want to patch soon.