S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 7, 2024

CVE-2016-6195 Scanner

Detects 'SQL Injection (SQLi)' vulnerability in vBulletin affects v. before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2016-6195
9.8
CVSS

SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 allows remote attackers to execute arbitrary SQL commands via the postids parameter to forumrunner/request.php, as exploited in the wild in July 2016.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

vBulletin is a commercial internet forum software package that enables their customers to create online communities or forums. Suitable for web developers, hobbyists and small enterprises, the software offers various features including template systems with fully customizable style options and modular extension to allow users to enhance and customize their forums according to their preference. Additionally, vBulletin software supports multiple database types and offers a powerful admin control panel to manage users, threads, and forum settings.

The vBulletin CVE-2016-6195 vulnerability was discovered in the forumrunner/includes/moderation.php file. This vulnerability enables hackers to execute arbitrary SQL commands by triggering the postids parameter in the forumrunner/request.php script. When successfully exploited, the vulnerability can grant unauthorized access, allowing attackers to manipulate the database, extract sensitive information, or execute malicious codes.

Exploitation of this vulnerability can lead to potentially devastating consequences. Hackers can easily use the exploit to gain privileged access and gain control of the targeted systems, making it possible to steal users' financial data, infiltrate email accounts, and even create backdoors to compromise other systems connected to the network. The affected websites can also suffer losses of user trust and in turn lower levels of business.

s4e.io's platform offers pro features that enable users to quickly and quickly identify vulnerabilities in their digital assets. By utilizing their advanced capabilities, users can rest knowing that their systems are secured and fully protected from potential hacking threats. Keep your online community safe and secure by investing in s4e.io today.

 

REFERENCES

Solution Advice

It is crucial to take immediate steps to protect your digital assets against the vBulletin security vulnerability. Here are some precautionary measures you can take:

  • Upgrade to a newer, secure version of the vBulletin software
  • Ensure that all user inputs are sanitized
  • Regularly monitor user activity logs to check for suspicious activity
  • Enforce strict access controls and permissions

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2016-6195 scanner - SQL Injection (SQLi) vulnerability in vBulletin | S4E