- EPSS 0.29%
- Published 03.06.2006 10:02:00
- Last modified 03.04.2025 01:03:51
SQL injection vulnerability in VBulletin 3.0.10 allows remote attackers to execute arbitrary SQL commands via the featureid parameter.
CVE-2006-2335
- EPSS 1.37%
- Published 12.05.2006 00:02:00
- Last modified 03.04.2025 01:03:51
Jelsoft vBulletin accepts uploads of Cascading Style Sheets (CSS) and processes them in a way that allows remote authenticated administrators to gain shell access by uploading a CSS file that contains PHP code, then selecting the file via the style c...
CVE-2006-2018
- EPSS 0.52%
- Published 25.04.2006 12:50:00
- Last modified 03.04.2025 01:03:51
SQL injection vulnerability in calendar.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL commands via the eventid parameter. NOTE: the affected version has been disputed by the vendor. It appears that this is the same issue a...
- EPSS 1.94%
- Published 18.04.2006 10:02:00
- Last modified 03.04.2025 01:03:51
PHP remote file inclusion vulnerability in VBulletin 3.5.1, 3.5.2, and 3.5.4 allows remote attackers to execute arbitrary code via a URL in the systempath parameter to (1) ImpExModule.php, (2) ImpExController.php, and (3) ImpExDisplay.php.
CVE-2006-1040
- EPSS 0.95%
- Published 07.03.2006 11:02:00
- Last modified 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in vBulletin 3.0.12 and 3.5.3 allows remote attackers to inject arbitrary web script or HTML via the email field, which is injected in profile.php but not sanitized in sendmsg.php.
CVE-2006-0080
- EPSS 0.66%
- Published 04.01.2006 06:03:00
- Last modified 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in vBulletin 3.5.2, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the title of an event, which is not properly filtered by (1) calendar.php and (2) reminder....
CVE-2005-4621
- EPSS 0.35%
- Published 31.12.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in the editavatar page in vBulletin 3.5.1 allows remote attackers to inject arbitrary web script or HTML via a URL in the remote avatar url field, in which the URL generates a parsing error, and possibly requi...
CVE-2005-3025
- EPSS 0.35%
- Published 21.09.2005 22:03:00
- Last modified 03.04.2025 01:03:51
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the loc parameter to (1) modcp/index.php or (2) admincp/index.php, or the ip parameter to (3) modcp/u...
CVE-2005-3024
- EPSS 0.52%
- Published 21.09.2005 22:03:00
- Last modified 03.04.2025 01:03:51
Multiple SQL injection vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) announcement parameter to announcement.php, the (2) thread[forumid] or (3) criteria parameters to thread.php, (...
CVE-2005-3023
- EPSS 0.35%
- Published 21.09.2005 22:03:00
- Last modified 03.04.2025 01:03:51
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) announcement.php, (2) admincalendar.php, (3) bbcode.php, (4) cronadmin.php, ...