Vulnerabilities > Jelsoft > Vbulletin > 3.0.10

DATE CVE VULNERABILITY TITLE RISK
2006-06-03 CVE-2006-2805 SQL Injection vulnerability in Jelsoft Vbulletin 3.0.10
SQL injection vulnerability in VBulletin 3.0.10 allows remote attackers to execute arbitrary SQL commands via the featureid parameter.
network
low complexity
jelsoft
5.0
2005-12-31 CVE-2005-4621 Cross-Site Scripting vulnerability in VBulletin
Cross-site scripting (XSS) vulnerability in the editavatar page in vBulletin 3.5.1 allows remote attackers to inject arbitrary web script or HTML via a URL in the remote avatar url field, in which the URL generates a parsing error, and possibly requiring a trailing extension such as .jpg.
network
jelsoft
4.3