HTTP: vBulletin nodeId SQL Injection

This signature detects attempts to exploit a known vulnerability against vBulletin nodeID. A successful attack can lead to command injection and arbitrary code execution.

Extended Description

vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.

Affected Products

Vbulletin vbulletin

References

CVE: CVE-2020-12720

Short Name
HTTP:SQL:INJ:VBULLETIN-NODEID
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2020-12720 Injection SQL nodeId vBulletin
Release Date
07/23/2020
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Vbulletin

CVSS Score

7.5

Found a potential security threat?