6.5

CVE-2015-3419

vBulletin 5.x through 5.1.6 allows remote authenticated users to bypass authorization checks and inject private messages into conversations via vectors related to an input validation failure.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Vbulletin ≫ Vbulletin Version 5.0.0 Update beta_11
Vbulletin ≫ Vbulletin Version 5.0.0 Update beta_28
Vbulletin ≫ Vbulletin Version 5.0.1
Vbulletin ≫ Vbulletin Version 5.0.2
Vbulletin ≫ Vbulletin Version 5.0.3
Vbulletin ≫ Vbulletin Version 5.0.4
Vbulletin ≫ Vbulletin Version 5.0.5
Vbulletin ≫ Vbulletin Version 5.1.0
Vbulletin ≫ Vbulletin Version 5.1.0 Update rc1
Vbulletin ≫ Vbulletin Version 5.1.1
Vbulletin ≫ Vbulletin Version 5.1.2 Update beta1
Vbulletin ≫ Vbulletin Version 5.1.2 Update rc1
Vbulletin ≫ Vbulletin Version 5.1.2 Update rc2
Vbulletin ≫ Vbulletin Version 5.1.3
Vbulletin ≫ Vbulletin Version 5.1.3 Update alpha5
Vbulletin ≫ Vbulletin Version 5.1.3 Update rc1
Vbulletin ≫ Vbulletin Version 5.1.4
Vbulletin ≫ Vbulletin Version 5.1.4 Update rc1
Vbulletin ≫ Vbulletin Version 5.1.5
Vbulletin ≫ Vbulletin Version 5.1.5 Update beta_1
Vbulletin ≫ Vbulletin Version 5.1.5 Update beta_3
Vbulletin ≫ Vbulletin Version 5.1.6
Vbulletin ≫ Vbulletin Version 5.1.6 Update beta_2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.98% 0.575
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.openwall.com/lists/oss-security/2015/04/24/4
Third Party Advisory
Mailing List
http://www.vbulletin.com/forum/forum/vbulletin-announcements/vbulletin-announcements_aa/4319488-security-patch-released-for-vbulletin-5-1-4-5-1-6-and-vbulletin-cloud
Vendor Advisory