This exploit demonstrates a code execution vulnerability in vBulletin 4.0.4 via manipulation of the 'comma' parameter in forumdisplay.php, allowing arbitrary command execution. It also references a potential JavaScript injection via vbulletin-core.js.
Classification
Working Poc 80%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target:vBulletin 4.0.4
No auth needed
Prerequisites:Access to the target vBulletin instance · vBulletin 4.0.4 installed