Vulnerabilities > CVE-2005-0511 - Unspecified vulnerability in Jelsoft Vbulletin
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.
Vulnerable Configurations
Exploit-Db
description vBulletin <= 3.0.6 php Code Injection. CVE-2005-0511. Webapps exploit for php platform id EDB-ID:832 last seen 2016-01-31 modified 2005-02-22 published 2005-02-22 reporter pokley source https://www.exploit-db.com/download/832/ title vBulletin <= 3.0.6 php Code Injection description vBulletin misc.php Template Name Arbitrary Code Execution. CVE-2005-0511. Webapps exploit for php platform id EDB-ID:16896 last seen 2016-02-02 modified 2010-07-25 published 2010-07-25 reporter metasploit source https://www.exploit-db.com/download/16896/ title vBulletin misc.php Template Name Arbitrary Code Execution
Metasploit
description | This module exploits an arbitrary PHP code execution flaw in the vBulletin web forum software. This vulnerability is only present when the "Add Template Name in HTML Comments" option is enabled. All versions of vBulletin prior to 3.0.7 are affected. |
id | MSF:EXPLOIT/UNIX/WEBAPP/PHP_VBULLETIN_TEMPLATE |
last seen | 2020-01-16 |
modified | 2017-07-24 |
published | 2007-01-05 |
references | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0511 |
reporter | Rapid7 |
source | https://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/unix/webapp/php_vbulletin_template.rb |
title | vBulletin misc.php Template Name Arbitrary Code Execution |
Nessus
NASL family | CGI abuses |
NASL id | VBULLETIN_CODE_EXECUTION.NASL |
description | The remote version of vBulletin fails to sanitize input to the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 17211 |
published | 2005-02-24 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/17211 |
title | vBulletin misc.php template Parameter PHP Code Injection |
code |
|
Packetstorm
data source | https://packetstormsecurity.com/files/download/82364/php_vbulletin_template.rb.txt |
id | PACKETSTORM:82364 |
last seen | 2016-12-05 |
published | 2009-10-30 |
reporter | str0ke |
source | https://packetstormsecurity.com/files/82364/vBulletin-misc.php-Template-Name-Arbitrary-Code-Execution.html |
title | vBulletin misc.php Template Name Arbitrary Code Execution |