Exploits in the Wild for vBulletin Pre-Auth RCE Vulnerability CVE-2020-17496

The values and parameters for the function staticRenderAjax are from $_REQUESTS, $_GET and $_POST, as shown by the red arrows.

The exploits can bypass a earlier fixed vulnerability, allowing for attackers to mail a crafted HTTP ask for with a specified template name and destructive PHP code, and sales opportunities to remote code execution.

Resource website link

Go through more on Malware updates & News

You may also like...

Leave a Reply

Your email address will not be published. Required fields are marked *