Vulnerabilities > Jelsoft > Vbulletin > 3.5.8

DATE CVE VULNERABILITY TITLE RISK
2006-05-12 CVE-2006-2335 Remote Security vulnerability in Jelsoft Vbulletin 3.5.8
Jelsoft vBulletin accepts uploads of Cascading Style Sheets (CSS) and processes them in a way that allows remote authenticated administrators to gain shell access by uploading a CSS file that contains PHP code, then selecting the file via the style chooser, which causes the PHP code to be executed.
network
low complexity
jelsoft
6.5