CVE-2016-6195 | vBulletin up to 4.2.2 PL4/4.2.3 moderation.php postids sql injection (EDB-40751 / ID 11672)
A vulnerability classified as critical was found in vBulletin up to 4.2.2 PL4/4.2.3. Affected by this vulnerability is an unknown functionality of the file forumrunner/includes/moderation.php. The manipulation of the argument postids leads to sql injection.
This vulnerability is known as CVE-2016-6195. The attack can be launched remotely. Furthermore, there is an exploit available.
A worm is spreading, which is automatically exploiting this vulnerability.
It is recommended to apply a patch to fix this issue.