CVE-2019-16759 is an unauthenticated remote code execution vulnerability in vBulletin 5.x through 5.5.4. The flaw is exposed through the Ajax widget rendering functionality and can be triggered by sending a crafted ajax/render/widget_php request with attacker-controlled data in the widgetConfig[code] parameter. The vulnerable behavior allows user-supplied code associated with the widget_php rendering path to be evaluated on the server, resulting in arbitrary command or code execution in the context of the web application.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a single Metasploit module targeting a remote code execution vulnerability (CVE-2019-16759) in vBulletin 5.x through 5.5.4. The exploit abuses the 'widgetConfig[code]' parameter in a POST request to the '/ajax/render/widget_php' endpoint, allowing arbitrary PHP code execution. The module supports multiple payloads, including Meterpreter (PHP in-memory), Unix, and Windows command execution, and can be customized through Metasploit's payload options. The code is structured as a standard Metasploit exploit module, with methods for checking vulnerability, executing commands, and handling payload delivery. The main fingerprintable endpoint is the '/ajax/render/widget_php' route, and the exploit is fully weaponized, allowing attackers to gain remote shell access or execute arbitrary commands on vulnerable vBulletin installations.
This repository is a mass exploitation toolkit for CVE-2019-16759, a pre-authentication remote code execution vulnerability in vBulletin versions 5.0.0 through 5.5.4. The structure includes: - `exploit.py`: An interactive exploit script that allows the user to execute arbitrary shell commands on a single vBulletin target by injecting PHP code via the 'widgetConfig[code]' POST parameter to the vulnerable endpoint `/index.php?routestring=ajax/render/widget_php`. - `bench.py`: A mass exploitation module that reads lists of target IPs (from `vbullet-443` and `vbullet-80`), sends the exploit payload to each, and optionally executes a specified command on all vulnerable hosts. It uses asynchronous requests for efficiency. - `vbulletin-scan.py`: A command-line tool that validates the IP lists, removes invalid entries, and orchestrates mass exploitation by calling `bench.py`. - `vbullet-443` and `vbullet-80`: Files containing lists of IP addresses (targets) for HTTPS and HTTP, respectively, typically generated from Shodan queries. - `README.md`: Documentation describing the vulnerability, usage instructions, and how to gather targets using Shodan. The main exploit capability is remote code execution via a POST request to the vulnerable vBulletin endpoint. The toolkit is designed for both single-target and mass exploitation. The endpoints of interest are the vulnerable PHP endpoint and the target IP lists. The code is operational and can be used to compromise vulnerable vBulletin installations at scale.
This repository contains a Bash script (vb-email-smtp.sh) that exploits CVE-2019-16759, a remote code execution vulnerability in vBulletin 5.x. The script takes a list of target URLs and, for each, sends a specially crafted POST request to the /ajax/render/widget_tabbedcontainer_tab_panel endpoint. The payload injects PHP code that reads the vBulletin configuration file to obtain database credentials, then queries the database to extract user email addresses and SMTP configuration. Results are saved to local files (result-email.txt and result-smtp.txt). The exploit is operational and automates the process of extracting sensitive information from vulnerable vBulletin installations. The repository also includes a README.md with usage instructions and a disclaimer.
This repository contains a Python exploit for CVE-2019-16759, targeting vBulletin versions 5.0 through 5.5.4. The exploit leverages an unauthenticated remote code execution vulnerability in the 'widget_php' functionality. The main file, 'exploit.py', prompts the user for a target site URL (HTTP or HTTPS), then sends a POST request to the vBulletin instance to test for vulnerability. If the target is vulnerable, the script provides an interactive shell, allowing the attacker to execute arbitrary system commands on the remote server via further POST requests. The repository is simple, with only a README and the exploit script, and is operational, providing a working interactive shell if the exploit succeeds. The attack vector is network-based, and the main fingerprintable endpoint is the POST request to the 'ajax/render/widget_php' route.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously disclosed vBulletin vulnerability referenced as the incomplete original fix related to CVE-2020-17496.
A remote code execution vulnerability leveraged by Morte Loader campaigns to gain initial access to SOHO routers, IoT devices, and web applications.
A remote code execution vulnerability leveraged by Morte Loader campaigns to compromise edge devices and web applications.
A vBulletin remote code execution vulnerability in versions 5.0.0 through 5.5.4 that allowed attacker-controlled PHP code execution via template rendering and whose patch was later bypassed by CVE-2020-17496.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.