VYPR

vBulletin 5 Connect

by Jelsoft

CVEs (1)

  • CVE-2015-7808Nov 24, 2015
    risk 0.09cvss epss 0.81

    The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in the arguments parameter to ajax/api/hook/decodeArguments.