RULE(RULE ID:333494)

Rule General Information
Release Date: 2021-04-16
Rule Name: vBulletin Authenticated Remote Code Execution Vulnerability (CVE-2019-17132)
Severity:
CVE ID:
Rule Protection Details
Description: vBulletin through 5.5.4 mishandles custom avatars.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: http://packetstormsecurity.com/files/154759/vBulletin-5.5.4-Remote-Code-Execution.html
http://seclists.org/fulldisclosure/2019/Oct/9
https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4423646-vbulletin-5-5-x-5-5-2-5-5-3-and-5-5-4-security-patch-level-2
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4423646-vbulletin-5-5-x-5-5-2-5-5-3-and-5-5-4-security-patch-level-2