Vulnerabilities > CVE-2006-3253 - Unspecified vulnerability in Jelsoft Vbulletin

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
jelsoft
exploit available

Summary

Cross-site scripting (XSS) vulnerability in member.php in vBulletin 3.5.x allows remote attackers to inject arbitrary web script or HTML via the u parameter. NOTE: the vendor has disputed this report, stating that they have been unable to replicate the issue and that "the userid parameter is run through our filtering system as an unsigned integer.

Exploit-Db

descriptionVbulletin 3.0.9/3.5.x Member.PHP Cross-Site Scripting Vulnerability. CVE-2006-3253 . Webapps exploit for php platform
idEDB-ID:28076
last seen2016-02-03
modified2006-06-20
published2006-06-20
reporterCrAzY.CrAcKeR
sourcehttps://www.exploit-db.com/download/28076/
titleVbulletin 3.0.9/3.5.x Member.PHP Cross-Site Scripting Vulnerability