EIP-2026-113013
PRE-CVEvBulletin < 4.2.2 - Memcache Remote Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113013. PoCs published by Joshua Rogers.
AI-analyzed exploit summary This exploit leverages an SSRF vulnerability in vBulletin's remote upload feature to send arbitrary data to loopback-only services like Memcached, allowing arbitrary code execution by manipulating the `pluginlist` value. The provided cURL command demonstrates the attack by injecting a malicious payload into Memcached via localhost.
Description
vBulletin < 4.2.2 - Memcache Remote Code Execution
Exploits (1)
This exploit leverages an SSRF vulnerability in vBulletin's remote upload feature to send arbitrary data to loopback-only services like Memcached, allowing arbitrary code execution by manipulating the `pluginlist` value. The provided cURL command demonstrates the attack by injecting a malicious payload into Memcached via localhost.