Vulnerabilities > Jelsoft > Vbulletin

DATE CVE VULNERABILITY TITLE RISK
2007-03-07 CVE-2007-1292 SQL-Injection vulnerability in vBulletin
SQL injection vulnerability in inlinemod.php in Jelsoft vBulletin before 3.5.8, and before 3.6.5 in the 3.6.x series, might allow remote authenticated users to execute arbitrary SQL commands via the postids parameter.
network
low complexity
jelsoft
7.5
2007-02-09 CVE-2007-0869 Cross-Site Scripting vulnerability in Jelsoft Vbulletin 3.6.4
Cross-site scripting (XSS) vulnerability in the Attachment Manager (admincp/attachment.php) in Jelsoft vBulletin 3.6.4 allows remote attackers to inject arbitrary web script or HTML via the Extension field.
network
jelsoft
4.3
2006-12-28 CVE-2006-6779 Unspecified vulnerability in Jelsoft Vbulletin
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin allows remote attackers to inject arbitrary web script or HTML via an SWF file that uses ActionScript to trigger execution of JavaScript.
network
jelsoft
6.8
2006-11-22 CVE-2006-6040 Cross-Site Scripting vulnerability in VBulletin Admin Control Panel
Multiple cross-site scripting (XSS) vulnerabilities in admincp/index.php in Jelsoft vBulletin 3.6.x allow remote attackers to inject arbitrary web script or HTML via (1) the prefs parameter in a buildnavprefs action or (2) the navprefs parameter in a savenavprefs action.
network
jelsoft
6.8
2006-10-03 CVE-2006-5104 SQL Injection vulnerability in Jelsoft VBulletin
SQL injection vulnerability in global.php in Jelsoft vBulletin 2.x allows remote attackers to execute arbitrary SQL commands via the templatesused parameter.
network
low complexity
jelsoft
7.5
2006-08-21 CVE-2006-4273 Unspecified vulnerability in Jelsoft Vbulletin 3.5.4/3.6.0
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 3.5.4 and 3.6.0 allows remote attackers to inject arbitrary web script or HTML by uploading an attachment with a .pdf extension that contains JavaScript, which is processed as script by Microsoft Internet Explorer 6.
network
jelsoft
6.8
2006-06-03 CVE-2006-2805 SQL Injection vulnerability in Jelsoft Vbulletin 3.0.10
SQL injection vulnerability in VBulletin 3.0.10 allows remote attackers to execute arbitrary SQL commands via the featureid parameter.
network
low complexity
jelsoft
5.0
2006-05-12 CVE-2006-2335 Remote Security vulnerability in Jelsoft Vbulletin 3.5.8
Jelsoft vBulletin accepts uploads of Cascading Style Sheets (CSS) and processes them in a way that allows remote authenticated administrators to gain shell access by uploading a CSS file that contains PHP code, then selecting the file via the style chooser, which causes the PHP code to be executed.
network
low complexity
jelsoft
6.5
2006-04-25 CVE-2006-2018 SQL-Injection vulnerability in vBulletin
SQL injection vulnerability in calendar.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL commands via the eventid parameter.
network
low complexity
jelsoft
7.5
2006-04-18 CVE-2006-1816 Remote Security vulnerability in Vbulletin 3.5.1/3.5.2/3.5.4
PHP remote file inclusion vulnerability in VBulletin 3.5.1, 3.5.2, and 3.5.4 allows remote attackers to execute arbitrary code via a URL in the systempath parameter to (1) ImpExModule.php, (2) ImpExController.php, and (3) ImpExDisplay.php.
network
low complexity
jelsoft
5.0