CVE-2017-17671 is a critical remote PHP code execution vulnerability affecting vBulletin versions through 5.3.x when deployed on Windows. Attackers can leverage directory traversal via "..\ " sequences in unauthenticated requests to include arbitrary files, such as Apache HTTP Server log files containing injected PHP code. This vulnerability carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. While no public exploit intelligence like Metasploit modules or ExploitDB entries are available, and community discussion is minimal, the potential for severe impact necessitates immediate patching for affected systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0.1, <= 5.3.3CPE matchmatch criteria | cpe:2.3:a:vbulletin:vbulletin:*:*:*:*:*:*:*:* | ||
5.0.0CPE matchmatch criteria | cpe:2.3:a:vbulletin:vbulletin:5.0.0:beta_11:*:*:*:*:*:* | ||
5.0.0CPE matchmatch criteria | cpe:2.3:a:vbulletin:vbulletin:5.0.0:beta_28:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.