EIP-2026-113010
PRE-CVEvBulletin 5.6.2 - 'widget_tabbedContainer_tab_panel' Remote Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113010. PoCs published by zenofex.
AI-analyzed exploit summary This exploit leverages an incomplete patch for CVE-2019-16759 in vBulletin 5.4.5 through 5.6.2, allowing pre-authentication remote code execution via a crafted POST request to the 'widget_tabbedContainer_tab_panel' endpoint. The exploit injects PHP code into the 'subWidgets[0][config][code]' parameter, which is then executed by the server.
Description
vBulletin 5.6.2 - 'widget_tabbedContainer_tab_panel' Remote Code Execution
Exploits (1)
This exploit leverages an incomplete patch for CVE-2019-16759 in vBulletin 5.4.5 through 5.6.2, allowing pre-authentication remote code execution via a crafted POST request to the 'widget_tabbedContainer_tab_panel' endpoint. The exploit injects PHP code into the 'subWidgets[0][config][code]' parameter, which is then executed by the server.