2.6

CVE-2006-3253

Exploit

Cross-site scripting (XSS) vulnerability in member.php in vBulletin 3.5.x allows remote attackers to inject arbitrary web script or HTML via the u parameter.  NOTE: the vendor has disputed this report, stating that they have been unable to replicate the issue and that "the userid parameter is run through our filtering system as an unsigned integer.

Data is provided by the National Vulnerability Database (NVD)
JelsoftVbulletin Version3.5.0
JelsoftVbulletin Version3.5.0_beta_1
JelsoftVbulletin Version3.5.0_beta_2
JelsoftVbulletin Version3.5.0_beta_3
JelsoftVbulletin Version3.5.0_beta_4
JelsoftVbulletin Version3.5.0_rc1
JelsoftVbulletin Version3.5.0_rc2
JelsoftVbulletin Version3.5.0_rc3
JelsoftVbulletin Version3.5.1
JelsoftVbulletin Version3.5.2
JelsoftVbulletin Version3.5.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 7.46% 0.914
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:N/I:P/A:N