Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: vBulletin vB 3.8.6 vulnerability SANS ISC InfoSec Forums

Participate: Learn more about our honeypot network

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
vBulletin vB 3.8.6 vulnerability

When teaching Security Essentials (sec401) we often talk about one of the more useful hacking tools in everyone's arsenal, a browser.  Wielding a browser in the right manner can expose all kinds of interesting information as is the case with vBulletin version 3.8.6. 

vBulletin, used to power online discussion sites has a serious flaw in vB 3.8.6. Browsing to the FAQ page on a vulnerable site and searching for the correct term will disclose the database credentials which can then be used to further compromise the site (  It shows that vulnerabilities do not need to be complex.  It also shows that code review, testing and of course input validation is essential. 

The vendor jumped on the issue quickly and provides a patch on their site.  Later versions of the product that are not vulnerable are also available. There do still seem to be sites up running the vulnerable code.  If yours is one of those, you may want to patch soon.



392 Posts
ISC Handler
Jul 23rd 2010

Sign Up for Free or Log In to start participating in the conversation!