Kusagadziriswa kwakakomba kusagadzikana muinjini yekugadzira mawebhu maforamu vBulletin (yakawedzerwa)

Zvakazarurwa ruzivo nezve isina kurongeka (0-zuva) yakakosha vulnerability (CVE-2019-16759) mune inoringana injini yekugadzira maforamu ewebhu. vBulletin, iyo inokutendera kuti uite kodhi pane sevha nekutumira yakanyatsogadzirirwa POST chikumbiro. Kushandiswa kwekushanda kunowanikwa kune dambudziko. vBulletin inoshandiswa nemapurojekiti mazhinji akavhurika, kusanganisira maforamu akavakirwa painjini iyi. Ubuntu, vhura, BSD masisitimu ΠΈ Slackware.

Kusagadzikana kuripo mu "ajax/render/widget_php" mubato, iyo inobvumira kupokana kodhi kodhi kupfuudzwa ne "widgetConfig[code]" parameter (iyo yekutanga kodhi inongopfuura, hautombodi kutiza chero chinhu) . Kurwiswa kwacho hakudi kuvimbiswa kweforum. Dambudziko rakasimbiswa mune zvese zvinoburitswa zvezvino vBulletin 5.x bazi (rakagadzirwa kubva 2012), kusanganisira iyo ichangoburwa kuburitswa 5.5.4. Iyo yekuvandudza ine kugadzirisa haisati yagadzirwa.

Kuwedzera 1: Kweshanduro 5.5.2, 5.5.3 uye 5.5.4 rakabudiswa zvigamba. Varidzi vekare 5.x inoburitswa vanorairwa kuti vatange vagadziridza masisitimu avo kune ichangoburwa shanduro kuti vabvise kusagadzikana, asi sechigadziriso. anogona comment out kudaidza β€œeval($code)” mu evalCode function code kubva pafaira inosanganisira/vb5/frontend/controller/bbcode.php.

Addendum 2: Kusagadzikana kwatova kushanda kuiswa zvekurwisa, spam mailings ΠΈ kusiya madoors. Tsanangudzo dzekurwiswa dzinogona kucherechedzwa mu http server logs nekuvapo kwezvikumbiro zvemutsara "ajax/render/widget_php".

Wedzero 3: surfaced mitsva yekushandiswa kwedambudziko ririkukurukurwa mukurwiswa kwekare; sezviri pachena, kusagadzikana kwakatoshandiswa kweanenge makore matatu. Uyezve, yakabudiswa script inogona kushandiswa kuita misa otomatiki kurwiswa kutsvaga masisitimu asina njodzi kuburikidza neiyo Shodan sevhisi.

Source: opennet.ru

Voeg