Vulnerabilities > CVE-2007-3326 - Unspecified vulnerability in Jelsoft Vbulletin 3.0.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Multiple directory traversal vulnerabilities in vBulletin 3.x.x allow remote attackers to redirect visitors to arbitrary local files via a .. (dot dot) in (1) the loc parameter to admincp/index.php and (2) the Hyperlink information URl field for post Topic in showthread.php, enabling cross-site scripting (XSS) and other attacks, a different vulnerability than CVE-2005-3025.2.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://securityreason.com/securityalert/2820
- http://securityreason.com/securityalert/2820
- http://www.securityfocus.com/archive/1/471835/100/0/threaded
- http://www.securityfocus.com/archive/1/471835/100/0/threaded
- http://www.securityfocus.com/archive/1/471838/100/0/threaded
- http://www.securityfocus.com/archive/1/471838/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34956
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34956