Record summary

CVE-2018-6200 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

vBulletin 3.x.x and 4.2.x through 4.2.5 has an open redirect via the redirector.php url parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMvBulletin - Open RedirectCVSS 6.1

vBulletin 3.x.x and 4.2.x through 4.2.5 contains an open redirect vulnerability via the redirector.php URL parameter. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

Impact

An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks.

Remediation

Apply the latest security patches and updates provided by vBulletin to fix the open redirect vulnerability.

WeaknessesCWE-601
Authors0x_Akoko, daffainfo
Template tagscvecve2018redirectvbulletinvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:vbulletin:vbulletin:*:*:*:*:*:*:*:*
Shodan: http.title:"powered by vbulletin"
Shodan: http.html:"powered by vbulletin"
Shodan: http.component:"vbulletin"
Shodan: cpe:"cpe:2.3:a:vbulletin:vbulletin"
FOFA: body="powered by vbulletin"
FOFA: title="powered by vbulletin"
Google: intext:"powered by vbulletin"
Google: intitle:"powered by vbulletin"

Source: ProjectDiscovery

References

2