ATTACK [PTsecurity] vBulletin <= 5.6.9 pre-auth RCE (CVE-2023-25135)
Sourceptrules/open
Fileptopen-attacks.rules
CreatedJuly 24, 2025
UpdatedJuly 24, 2025
Classificationattempted-admin
alert http any any -> any any (msg:"ATTACK [PTsecurity] vBulletin <= 5.6.9 pre-auth RCE (CVE-2023-25135)"; flow:established, to_server ; http.method; content:"POST"; http.request_body; content:"googlelogin_vendor_autoload"; nocase; content:"Monolog"; distance:0; content:"Handler"; distance:0; content:"SyslogUdpHandler"; distance:0; content:"Monolog"; distance:0; content:"Handler"; distance:0; content:"BufferHandler"; distance:0; content:"current"; distance:0; reference:cve, 2023-25135 ; reference:url, ambionics.io/blog/vbulletin-unserializable-but-unreachable ; reference:url, rules.ptsecurity.com ; classtype:attempted-admin; sid:10008756; rev:1;)
References
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!