Total vulnerabilities in the database
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
Software | From | Fixed in |
---|---|---|
vbulletin / vbulletin | 5.0.0 | 5.5.4.x |