Ubungozi obungalungisiwe enjinini bokudala izinkundla zewebhu vBulletin (kwengeziwe)

Kwembulwa ulwazi mayelana nokuba sengozini okungalungiswanga (izinsuku ezi-0) (i-CVE-2019-16759) enjinini yobunikazi yokudala izinkundla zewebhu vBulletin, okukuvumela ukuthi wenze ikhodi kuseva ngokuthumela isicelo sokuTHUMELA esiklanywe ngokukhethekile. Ukuxhashazwa okusebenzayo kuyatholakala kule nkinga. I-vBulletin isetshenziswa amaphrojekthi amaningi avulekile, kufaka phakathi izinkundla ezisuselwe kule njini. Ubuntu, vulaSUSE, Izinhlelo ze-BSD ΠΈ Slackware.

Ubungozi bukhona kusibambi se-β€œajax/render/widget_php”, esivumela ikhodi yegobolondo ngokunganaki ukuthi idluliswe kupharamitha ye-β€œwidgetConfig[code]” (ikhodi yokuqalisa imane idlule, awudingi ngisho nokubalekela noma yini) . Ukuhlasela akudingi ukuqinisekiswa kwenkundla. Inkinga iqinisekisiwe kukho konke ukukhishwa kwegatsha lamanje le-vBulletin 5.x (elithuthukiswe kusukela ngo-2012), kuhlanganise nokukhishwa kwakamuva kakhulu okungu-5.5.4. Isibuyekezo esinokulungiswa akukakalungiselelwa.

Isengezo 1: Ezinguqulo 5.5.2, 5.5.3 kanye 5.5.4 khululiwe amapheshana. Abanikazi bokukhishwa kwe-5.x endala bayelulekwa ukuthi baqale babuyekeze amasistimu abo ezinguqulweni zakamuva ezisekelwayo ukuze baqede ubungozi, kodwa njengendlela yokusingatha izinkinga. can phawula ukubiza β€œi-eval($code)” kukhodi yokusebenza ye-evalCode efayelini ihlanganisa/vb5/frontend/controller/bbcode.php.

Isengezo 2: Ukuba sengozini sekuvele kuyasebenza kuyasebenza ngokuhlaselwa, ukuthunyelwa kogaxekile ΠΈ eshiya iminyango. Imikhondo yokuhlasela ingabonwa kulogi yeseva ye-http ngokuba khona kwezicelo zomugqa "ajax/render/widget_php".

Isengezo 3: kwavela iminonjana yokusetshenziswa kwenkinga okuxoxwa ngayo ekuhlaselweni okudala; ngokusobala, ubungozi sebuvele busetshenziswe cishe iminyaka emithathu. Ngaphandle kwalokho, eshicilelwe iskripthi esingasetshenziswa ukwenza ukuhlasela okuzenzakalelayo okukhulu ukucinga amasistimu asengozini ngesevisi ye-Shodan.

Source: opennet.ru

Engeza amazwana