image.php in vBulletin 3.0.9 and earlier allows remote attackers with access to the administrator panel to upload arbitrary files via the upload action.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/22325 | vdb entry |
http://morph3us.org/advisories/20050917-vbulletin-3.0.8.txt | patch vendor advisory exploit |
http://marc.info/?l=bugtraq&m=112715150320677&w=2 | mailing list |
http://secunia.com/advisories/16873/ | patch vendor advisory third party advisory |