Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-17672

EPSS 14.70% · P95
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2017-17672

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circumstances, code execution, because of unsafe usage of PHP's unserialize() in vB_Library_Template's cacheTemplates() function, which is a publicly exposed API. This is exploited with the templateidlist parameter to ajax/api/template/cacheTemplates.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
vBulletin 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
vBulletin是美国Internet Brands和vBulletin Solutions公司共同开发的一款开源的商业Web论坛程序。 vBulletin 5.3.x及之前的版本中存在反序列化漏洞,该漏洞源于在vB_Library_Template的‘cacheTemplates()’函数中程序没有安全的使用‘unserialize()’函数。攻击者可利用该漏洞删除任意文件,执行代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2017-17672

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-17672

Please Login to view more intelligence information

Same Patch Batch · n/a · 2017-12-14 · 32 CVEs total

CVE-2017-17526Bernard Parisse Giac 安全漏洞
CVE-2017-17671vBulletin for Windows 安全漏洞
CVE-2017-17684Panda Global Protection 安全漏洞
CVE-2017-17683Panda Global Protection 安全漏洞
CVE-2017-17682ImageMagick 资源管理错误漏洞
CVE-2017-17681ImageMagick 安全漏洞
CVE-2017-17680ImageMagick 安全漏洞
CVE-2017-17535Bob Hepple gjots2 安全漏洞
CVE-2017-17534Mensis 安全漏洞
CVE-2017-17533Tkabber 安全漏洞
CVE-2017-17532Kiwi 安全漏洞
CVE-2017-17531GNU GLOBAL 安全漏洞
CVE-2017-17530Geomview 注入漏洞
CVE-2017-17529AbiWord 安全漏洞
CVE-2017-17528ScummVM 安全漏洞
CVE-2017-17527PasDoc 安全漏洞
CVE-2017-16355Phusion Passenger 安全漏洞
CVE-2017-17525xTuple PostBooks 安全漏洞
CVE-2017-17524SWI-Prolog 安全漏洞
CVE-2017-17522Python 安全漏洞

Showing top 20 of 32 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2017-17672

No comments yet


Leave a comment