7.5

CVE-2005-0511

misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Jelsoft ≫ Vbulletin Version 2.0
Jelsoft ≫ Vbulletin Version 2.0.1
Jelsoft ≫ Vbulletin Version 2.0.2
Jelsoft ≫ Vbulletin Version 2.0_beta_2
Jelsoft ≫ Vbulletin Version 2.0_beta_3
Jelsoft ≫ Vbulletin Version 2.2.0
Jelsoft ≫ Vbulletin Version 2.2.1
Jelsoft ≫ Vbulletin Version 2.2.2
Jelsoft ≫ Vbulletin Version 2.2.3
Jelsoft ≫ Vbulletin Version 2.2.4
Jelsoft ≫ Vbulletin Version 2.2.5
Jelsoft ≫ Vbulletin Version 2.2.6
Jelsoft ≫ Vbulletin Version 2.2.7
Jelsoft ≫ Vbulletin Version 2.2.8
Jelsoft ≫ Vbulletin Version 2.2.9_can
Jelsoft ≫ Vbulletin Version 2.3.0
Jelsoft ≫ Vbulletin Version 2.3.3
Jelsoft ≫ Vbulletin Version 2.3.4
Jelsoft ≫ Vbulletin Version 3.0.0
Jelsoft ≫ Vbulletin Version 3.0.0_beta_2
Jelsoft ≫ Vbulletin Version 3.0.0_can4
Jelsoft ≫ Vbulletin Version 3.0.0_rc4
Jelsoft ≫ Vbulletin Version 3.0.1
Jelsoft ≫ Vbulletin Version 3.0.2
Jelsoft ≫ Vbulletin Version 3.0.3
Jelsoft ≫ Vbulletin Version 3.0.4
Jelsoft ≫ Vbulletin Version 3.0.5
Jelsoft ≫ Vbulletin Version 3.0.6
Jelsoft ≫ Vbulletin Version 3.0_beta_2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 35.82% 0.983
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://marc.info/?l=bugtraq&m=110910899415763&w=2
http://secunia.com/advisories/14326
Patch
Vendor Advisory
http://www.securityfocus.com/bid/12622
http://www.vbulletin.com/forum/showthread.php?postid=819562