Description
An SQL injection vulnerability affects vBulletin 5.6.1 and earlier versions. The SQL injection vulnerability affects the vBulletin endpoint /ajax/api/content_infraction/getIndexableContent and can be exploited via the POST parameter nodeId[nodeid].
The following patches are available for the following versions of vBulletin Connect:
- 5.6.1 Patch Level 1
- 5.6.0 Patch Level 1
- 5.5.6 Patch Level 1
If you are using a version of vBulletin 5 Connect prior to 5.5.6, it is imperative that you upgrade as soon as possible.
Remediation
Upgrade to the latest version of vBulletin 5.
References
Related Vulnerabilities
WordPress Plugin WP Bannerize 'ajax_clickcounter.php' SQL Injection (2.8.6)
WordPress Plugin bbPress Like Button SQL Injection (1.5)
WordPress Plugin Side Menu Lite-add sticky fixed buttons SQL Injection (2.2.1)
WordPress Plugin PureHTML 'alter.php' SQL Injection (1.0.0)
WordPress 3.1.3 Multiple SQL Injection Vulnerabilities (3.1 - 3.1.3)