Vulnerabilities > CVE-2013-3528 - PHP Code Injection vulnerability in Vanillaforums Vanilla

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
vanillaforums
exploit available

Summary

Unspecified vulnerability in the update check in Vanilla Forums before 2.0.18.8 has unspecified impact and remote attack vectors, related to "object injection."

Exploit-Db

descriptionVanilla Forums 2.0 - 2.0.18.5 (class.utilitycontroller.php) - PHP Object Injection Vulnerability. CVE-2013-2749,CVE-2013-3528. Webapps exploit for php platform
idEDB-ID:29512
last seen2016-02-03
modified2013-11-08
published2013-11-08
reporterEgiX
sourcehttps://www.exploit-db.com/download/29512/
titleVanilla Forums 2.0 - 2.0.18.5 class.utilitycontroller.php - PHP Object Injection Vulnerability

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/123529/KIS-2013-09.txt
idPACKETSTORM:123529
last seen2016-12-05
published2013-10-07
reporterEgiX
sourcehttps://packetstormsecurity.com/files/123529/Vanilla-Forums-2.0.18.5-Local-File-Inclusion.html
titleVanilla Forums 2.0.18.5 Local File Inclusion

Seebug

bulletinFamilyexploit
descriptionNo description provided by source.
idSSV:83010
last seen2017-11-19
modified2014-07-01
published2014-07-01
reporterRoot
sourcehttps://www.seebug.org/vuldb/ssvid-83010
titleVanilla Forums 2.0 - 2.0.18.5 (class.utilitycontroller.php) - PHP Object Injection Vulnerability