Vulnerabilities > Jelsoft
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2007-05-30 | CVE-2007-2908 | HTML Injection vulnerability in VBulletin Calendar.PHP Cross-site scripting (XSS) vulnerability in calendar.php in Jelsoft vBulletin before 3.6.6 allows remote attackers to inject arbitrary web script or HTML via the title field in a single add action. network jelsoft | 4.3 |
2007-03-21 | CVE-2007-1573 | SQL Injection vulnerability in Jelsoft Vbulletin 3.6.4 SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin 3.6.5 allows remote authenticated administrators to execute arbitrary SQL commands via the "Attached Before" field. | 6.0 |
2007-03-08 | CVE-2007-1342 | HTML Injection vulnerability in RETIRED: VBulletin Event Admincp/Index.PHP RSS Cross-site scripting (XSS) vulnerability in admincp/index.php in Jelsoft vBulletin 3.6.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the add rss url form. network jelsoft | 4.3 |
2007-03-07 | CVE-2007-1292 | SQL-Injection vulnerability in vBulletin SQL injection vulnerability in inlinemod.php in Jelsoft vBulletin before 3.5.8, and before 3.6.5 in the 3.6.x series, might allow remote authenticated users to execute arbitrary SQL commands via the postids parameter. | 7.5 |
2007-02-09 | CVE-2007-0869 | Cross-Site Scripting vulnerability in Jelsoft Vbulletin 3.6.4 Cross-site scripting (XSS) vulnerability in the Attachment Manager (admincp/attachment.php) in Jelsoft vBulletin 3.6.4 allows remote attackers to inject arbitrary web script or HTML via the Extension field. network jelsoft | 4.3 |
2006-12-28 | CVE-2006-6779 | Unspecified vulnerability in Jelsoft Vbulletin Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin allows remote attackers to inject arbitrary web script or HTML via an SWF file that uses ActionScript to trigger execution of JavaScript. network jelsoft | 6.8 |
2006-11-22 | CVE-2006-6040 | Cross-Site Scripting vulnerability in VBulletin Admin Control Panel Multiple cross-site scripting (XSS) vulnerabilities in admincp/index.php in Jelsoft vBulletin 3.6.x allow remote attackers to inject arbitrary web script or HTML via (1) the prefs parameter in a buildnavprefs action or (2) the navprefs parameter in a savenavprefs action. network jelsoft | 6.8 |
2006-10-03 | CVE-2006-5104 | SQL Injection vulnerability in Jelsoft VBulletin SQL injection vulnerability in global.php in Jelsoft vBulletin 2.x allows remote attackers to execute arbitrary SQL commands via the templatesused parameter. | 7.5 |
2006-08-21 | CVE-2006-4273 | Unspecified vulnerability in Jelsoft Vbulletin 3.5.4/3.6.0 Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 3.5.4 and 3.6.0 allows remote attackers to inject arbitrary web script or HTML by uploading an attachment with a .pdf extension that contains JavaScript, which is processed as script by Microsoft Internet Explorer 6. network jelsoft | 6.8 |
2006-06-03 | CVE-2006-2805 | SQL Injection vulnerability in Jelsoft Vbulletin 3.0.10 SQL injection vulnerability in VBulletin 3.0.10 allows remote attackers to execute arbitrary SQL commands via the featureid parameter. | 5.0 |