RULE(RULE ID:311738)

Rule General Information
Release Date: 2015-05-20
Rule Name: Vbulletin SQL Injection Vulnerability (CVE-2014-5102)
Severity:
CVE ID:
Rule Protection Details
Description: SQL injection vulnerability in vBulletin 5.0.4 through 5.1.3 Alpha 5 allows remote attackers to execute arbitrary SQL commands via the criteria[startswith] parameter to ajax/render/memberlist_items.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Other Unix, Linux
Reference: SecurityFocusBID:68709
Solutions
The vendor has updated advisory on its official website. Please check it for more information.