Vulnerability record · CVE-2015-7808 · published 24 November 2015
CVE-2015-7808: vBulletin 5 Connect PHP object injection in decodeArguments
VVbulletin · Vbulletin
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 fails to validate the arguments parameter, allowing PHP object injection. A crafted serialized object sent to ajax/api/hook/decodeArguments can lead to arbitrary PHP code execution on the server.
Description
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in the arguments parameter to ajax/api/hook/decodeArguments.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
critical priorityUnauthenticated remote code execution with public exploits and in-the-wild activity, despite not being in CISA KEV.
What it is
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 fails to validate the arguments parameter, allowing PHP object injection. A crafted serialized object sent to ajax/api/hook/decodeArguments can lead to arbitrary PHP code execution on the server.
Impact
A remote attacker can execute arbitrary PHP code on the vBulletin server, leading to full compromise of the web application and its data.
Attack surface
Reachable over the network via HTTP requests to ajax/api/hook/decodeArguments; no authentication or user interaction is required per the CVSS vector AV:N/AC:L/Au:N.
Exploitation
Multiple public exploit references exist, including a Check Point 0-day disclosure and in-the-wild reports; EPSS is 0.80635 (99.6th percentile), but CISA KEV does not list it.
What to do
- Upgrade vBulletin 5 Connect to a version later than 5.1.9 that fixes the decodeArguments unserialization flaw.
- If immediate upgrade is not possible, restrict or block access to ajax/api/hook/decodeArguments at the web server or WAF.
- Apply vendor patches or hotfixes as soon as they are available.
- Monitor for and remove any webshells or unexpected PHP files that may have been placed after exploitation.
Detection
- Inspect HTTP requests for POST parameters named arguments containing serialized PHP object strings (e.g., O: or a: patterns) to ajax/api/hook/decodeArguments.
- Monitor web server logs for requests to ajax/api/hook/decodeArguments with unusual or malformed arguments.
- Use file integrity monitoring to detect new or modified PHP files in the web root.
- Review PHP error logs for unserialize warnings or object injection errors.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-7808 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-7808), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.