One little inconsistency here is that the facebook announcement says the vulnerability is in vB4 and vB5 and they hacked vBulletin.
org. vBulletin.org uses vb3.6.12. Why didn't the announcement say the vulnerability is in vB3 as well?
If you're so sure this is true then buy their patch (NOT!!!!!)
Quote:
Originally Posted by Inj3ct0r Exploit DataBase
All those wishing to buy a vulnerability and patch your forum : h t t p ://1337day.com/exploit/description/21518
|