← All CVEs

CVE-2016-6483

high · 8.6

The media-file upload feature in vBulletin before 3.8.7 Patch Level 6, 3.8.8 before Patch Level 2, 3.8.9 before Patch Level 1, 4.x before 4.2.2 Patch Level 6, 4.2.3 before Patch Level 2, 5.x before 5.2.0 Patch Level 3, 5.2.1 before Patch Level 1, and 5.2.2 before Patch Level 1 allows remote attackers to conduct SSRF attacks via a crafted URL that results in a Redirection HTTP status code.

8.6
CVSS
11.9%
EPSS (exploit prob.)
96th
EPSS percentile
2016-09-02
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

Weaknesses

CWE-918

Affected products

VendorProductAffected versions
vbulletinvbulletin3.8.7
vbulletinvbulletin3.8.8
vbulletinvbulletin3.8.9
vbulletinvbulletin4.2.2
vbulletinvbulletin4.2.3
vbulletinvbulletin5.2.0
vbulletinvbulletin5.2.1
vbulletinvbulletin5.2.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-6483