Vbulletin

Vbulletin

50 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 14.56%
  • Veröffentlicht 02.09.2016 01:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The media-file upload feature in vBulletin before 3.8.7 Patch Level 6, 3.8.8 before Patch Level 2, 3.8.9 before Patch Level 1, 4.x before 4.2.2 Patch Level 6, 4.2.3 before Patch Level 2, 5.x before 5.2.0 Patch Level 3, 5.2.1 before Patch Level 1, and...

  • EPSS 86.43%
  • Veröffentlicht 30.08.2016 19:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1 allows remote attackers to execute arbitrary SQL commands via the postids parameter to forumrunner/request.php, ...

Exploit
  • EPSS 79.04%
  • Veröffentlicht 24.11.2015 20:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in the arguments parameter to ajax/api/h...

Exploit
  • EPSS 0.12%
  • Veröffentlicht 02.01.2015 19:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Cross-site request forgery (CSRF) vulnerability in the Moderator Control Panel in vBulletin 4.2.2 allows remote attackers to hijack the authentication of administrators for requests that (1) ban a user via the username parameter in a dobanuser action...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 06.11.2014 15:55:14
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Open redirect vulnerability in go.php in vBulletin 4.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.

Exploit
  • EPSS 0.91%
  • Veröffentlicht 25.10.2014 00:55:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in admincp/apilog.php in vBulletin 4.2.2 and earlier, and 5.0.x through 5.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted XMLRPC API request, as demonstrated using th...

Exploit
  • EPSS 1.31%
  • Veröffentlicht 15.10.2014 14:55:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and earlier allows remote authenticated users to execute arbitrary SQL commands via the conceptid argument in an xmlrpc API request.

Exploit
  • EPSS 0.4%
  • Veröffentlicht 25.07.2014 19:55:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

SQL injection vulnerability in vBulletin 5.0.4 through 5.1.3 Alpha 5 allows remote attackers to execute arbitrary SQL commands via the criteria[startswith] parameter to ajax/render/memberlist_items.

  • EPSS 0.44%
  • Veröffentlicht 30.04.2014 14:22:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 5.1.1 Alpha 9 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to privatemessage/new/, (2) the folderid parameter to a private message in privatemessa...

Exploit
  • EPSS 74.43%
  • Veröffentlicht 19.10.2013 10:36:09
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid, htmldata[password], htmldata[confirmpassword], and htmldata[email] parameters, as exploited in the wild in October 201...