This document describes a username spoofing vulnerability in vBulletin 3.8.4 and 3.8.5, where an attacker can register with a username containing ASCII code � to impersonate an admin user. The writeup includes steps to exploit and patch the vulnerability.
Classification
Writeup 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target:vBulletin 3.8.4 & 3.8.5
No auth needed
Prerequisites:Access to the registration page of a vulnerable vBulletin instance