Vulnerabilities > Jelsoft

DATE CVE VULNERABILITY TITLE RISK
2002-12-31 CVE-2002-1678 Cross-Site Scripting vulnerability in VBulletin
Cross-site scripting (XSS) vulnerability in memberlist.php in Jelsoft vBulletin 2.0 rc 2 through 2.2.4 allows remote attackers to steal authentication credentials by injecting script into $letterbits.
network
jelsoft
4.3
2002-12-31 CVE-2002-1660 OS Command Injection vulnerability in Jelsoft Vbulletin
calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command parameter.
network
low complexity
jelsoft CWE-78
7.5
2001-06-27 CVE-2001-0475 Unspecified vulnerability in Jelsoft Vbulletin
index.php in Jelsoft vBulletin does not properly initialize a PHP variable that is used to store template information, which allows remote attackers to execute arbitrary PHP code via special characters in the templatecache parameter.
network
low complexity
jelsoft
7.5