Vulnerabilities > Jelsoft > Vbulletin > 3.6.4

DATE CVE VULNERABILITY TITLE RISK
2007-03-21 CVE-2007-1573 SQL Injection vulnerability in Jelsoft Vbulletin 3.6.4
SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin 3.6.5 allows remote authenticated administrators to execute arbitrary SQL commands via the "Attached Before" field.
network
jelsoft CWE-89
6.0
2007-03-07 CVE-2007-1292 SQL-Injection vulnerability in vBulletin
SQL injection vulnerability in inlinemod.php in Jelsoft vBulletin before 3.5.8, and before 3.6.5 in the 3.6.x series, might allow remote authenticated users to execute arbitrary SQL commands via the postids parameter.
network
low complexity
jelsoft
7.5
2007-02-09 CVE-2007-0869 Cross-Site Scripting vulnerability in Jelsoft Vbulletin 3.6.4
Cross-site scripting (XSS) vulnerability in the Attachment Manager (admincp/attachment.php) in Jelsoft vBulletin 3.6.4 allows remote attackers to inject arbitrary web script or HTML via the Extension field.
network
jelsoft
4.3
2006-12-28 CVE-2006-6779 Unspecified vulnerability in Jelsoft Vbulletin
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin allows remote attackers to inject arbitrary web script or HTML via an SWF file that uses ActionScript to trigger execution of JavaScript.
network
jelsoft
6.8