vBulletin 5.6.1 SQL Injection
Posted by deepcore on June 3, 2020 – 5:03 pm
This Metasploit module exploits a SQL injection vulnerability found in vBulletin versions 5.6.1 and below. This module uses the getIndexableContent vulnerability to reset the administrator’s password and it then uses the administrators login information to achieve remote code execution on the target. This module has been tested successfully on vBulletin version 5.6.1 on the Ubuntu Linux distribution.
Post a reply
You must be logged in to post a comment.