Vulnerabilities > Jelsoft

DATE CVE VULNERABILITY TITLE RISK
2006-05-12 CVE-2006-2335 Remote Security vulnerability in Jelsoft Vbulletin 3.5.8
Jelsoft vBulletin accepts uploads of Cascading Style Sheets (CSS) and processes them in a way that allows remote authenticated administrators to gain shell access by uploading a CSS file that contains PHP code, then selecting the file via the style chooser, which causes the PHP code to be executed.
network
low complexity
jelsoft
6.5
2006-04-25 CVE-2006-2018 SQL-Injection vulnerability in vBulletin
SQL injection vulnerability in calendar.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL commands via the eventid parameter.
network
low complexity
jelsoft
7.5
2006-04-18 CVE-2006-1816 Remote Security vulnerability in Vbulletin 3.5.1/3.5.2/3.5.4
PHP remote file inclusion vulnerability in VBulletin 3.5.1, 3.5.2, and 3.5.4 allows remote attackers to execute arbitrary code via a URL in the systempath parameter to (1) ImpExModule.php, (2) ImpExController.php, and (3) ImpExDisplay.php.
network
low complexity
jelsoft
5.0
2006-04-07 CVE-2006-1673 Cross-Site Scripting vulnerability in vBulletin
Cross-site scripting (XSS) vulnerability in vbugs.php in Dark_Wizard vBug Tracker 3.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the sortorder parameter.
network
high complexity
jelsoft
2.6
2006-03-24 CVE-2006-1382 Remote File Include vulnerability in VBulletin ImpEx
PHP remote file inclusion vulnerability in impex/ImpExData.php in vBulletin ImpEx module 1.74, when register_globals is disabled, allows remote attackers to include arbitrary files via the systempath parameter.
network
low complexity
jelsoft
7.5
2006-03-07 CVE-2006-1040 HTML Injection vulnerability in Jelsoft Vbulletin 3.0.12/3.5.3
Cross-site scripting (XSS) vulnerability in vBulletin 3.0.12 and 3.5.3 allows remote attackers to inject arbitrary web script or HTML via the email field, which is injected in profile.php but not sanitized in sendmsg.php.
network
jelsoft
4.3
2006-01-04 CVE-2006-0080 HTML Injection vulnerability in Jelsoft Vbulletin 3.5.2
Cross-site scripting (XSS) vulnerability in vBulletin 3.5.2, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the title of an event, which is not properly filtered by (1) calendar.php and (2) reminder.php.
network
jelsoft
4.3
2005-12-31 CVE-2005-4621 Cross-Site Scripting vulnerability in VBulletin
Cross-site scripting (XSS) vulnerability in the editavatar page in vBulletin 3.5.1 allows remote attackers to inject arbitrary web script or HTML via a URL in the remote avatar url field, in which the URL generates a parsing error, and possibly requiring a trailing extension such as .jpg.
network
jelsoft
4.3
2005-09-21 CVE-2005-3025 Cross-Site Scripting vulnerability in vBulletin
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the loc parameter to (1) modcp/index.php or (2) admincp/index.php, or the ip parameter to (3) modcp/user.php or (4) admincp/usertitle.php.
network
jelsoft
4.3
2005-09-21 CVE-2005-3024 SQL-Injection vulnerability in vBulletin
Multiple SQL injection vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) announcement parameter to announcement.php, the (2) thread[forumid] or (3) criteria parameters to thread.php, (4) userid parameter to user.php, the (5) calendarcustomfieldid, (6) calendarid, (7) moderatorid, (8) holidayid, (9) calendarmoderatorid, or (10) calendar[0] parameters to admincalendar.php, (11) the cronid parameter to cronlog.php, (12) user[usergroupid][0] parameter to email.php, (13) help[0] parameter to help.php, the (14) limitnumber or (15) limitstart parameter to user.php, the (16) usertitleid or (17) ids parameters to usertitle.php, (18) rvt[0] parameter to language.php, (19) keep[0] parameter to phrase.php, (20) dostyleid parameter to template.php, (21) thread[forumid] parameter to thread.php, or (22) usertools.php.
network
low complexity
jelsoft
7.5