Emergency vBulletin patch fixes dangerous SQL injection vulnerability

Attackers could exploit the flaw to steal information from the databases of websites running vBulletin 5

Developers of the popular vBulletin Internet forum software have issued emergency patches Wednesday in order to fix a SQL injection vulnerability that could allow attackers to read and manipulate information stored in the databases of vBulletin-based sites.

Code patches that need to be applied manually were released for versions 5.0.4, 5.0.5, 5.1.0, 5.1.1 and 5.1.2 of vBulletin and can be downloaded by registered customers. The vulnerability only affects vBulletin 5 -- officially known as vBulletin 5 Connect -- and not vBulletin 4.

"The issue may allow attackers to perform SQL injection attacks on your database," said Wayne Luke, the vBulletin technical support lead, in an announcement on the official support forum. "It is recommended that all users update as soon as possible."

Customers who have their sites hosted on the vBulletin Cloud service will get the patches automatically as part of regular maintenance, Luke said. VBulletin version 5.1.3, which is currently in alpha stage of development and not ready for production environments, will include the fix in its next release, he said.

SQL injection is a relatively common but dangerous Web application vulnerability that allows attackers to execute malicious SQL commands against a site's database. It can be used to read potentially sensitive information from the database like user details, to write bogus information into the database and in certain cases to even execute arbitrary code on the server.

According to vBulletin Solutions, the company that develops the commercial forum software, over 100,000 community websites run on vBulletin, including some operated by Zynga, Electronic Arts, Sony Pictures, NASA, Valve Corporation and other well known companies.

Attackers have targeted vBulletin-based websites before. Last year hackers stole user email addresses and password hashes from UbuntuForums.org, a community forum for the Ubuntu Linux distribution with over 1.8 million registered accounts. The support forum for the openSUSE Linux distribution, which also runs on vBulletin, was hacked twice in the past; last time in January by a hacker who claimed to have used a previously unknown vBulletin exploit.

The official vBulletin forum itself was compromised in November 2013 after a staging server was accidentally left vulnerable to a vBulletin security issue patched several weeks earlier.

According to a video posted Monday on YouTube, the new SQL injection vulnerability was discovered and reported to the vBulletin developers by a user named Nytro, who's the administrator of a hacker community forum called the Romanian Security Team (RST). Nytro confirmed the availability of patches for the flaw he found Thursday on the RST forum and said that he plans to release details about the exploit in a few days, after people have a chance to update.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags patchessecuritypatch managementExploits / vulnerabilitiesvBulletin Solutions

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Lucian Constantin

IDG News Service
Show Comments

Cool Tech

SanDisk MicroSDXC™ for Nintendo® Switch™

Learn more >

Breitling Superocean Heritage Chronographe 44

Learn more >

Toys for Boys

Family Friendly

Panasonic 4K UHD Blu-Ray Player and Full HD Recorder with Netflix - UBT1GL-K

Learn more >

Stocking Stuffer

Razer DeathAdder Expert Ergonomic Gaming Mouse

Learn more >

Christmas Gift Guide

Click for more ›

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Walid Mikhael

Brother QL-820NWB Professional Label Printer

It’s easy to set up, it’s compact and quiet when printing and to top if off, the print quality is excellent. This is hands down the best printer I’ve used for printing labels.

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

David Coyle

Brother PocketJet PJ-773 A4 Portable Thermal Printer

I rate the printer as a 5 out of 5 stars as it has been able to fit seamlessly into my busy and mobile lifestyle.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?