Vulnerabilities > Jelsoft > Vbulletin > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2006-11-22 | CVE-2006-6040 | Cross-Site Scripting vulnerability in VBulletin Admin Control Panel Multiple cross-site scripting (XSS) vulnerabilities in admincp/index.php in Jelsoft vBulletin 3.6.x allow remote attackers to inject arbitrary web script or HTML via (1) the prefs parameter in a buildnavprefs action or (2) the navprefs parameter in a savenavprefs action. network jelsoft | 6.8 |
2006-08-21 | CVE-2006-4273 | Unspecified vulnerability in Jelsoft Vbulletin 3.5.4/3.6.0 Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 3.5.4 and 3.6.0 allows remote attackers to inject arbitrary web script or HTML by uploading an attachment with a .pdf extension that contains JavaScript, which is processed as script by Microsoft Internet Explorer 6. network jelsoft | 6.8 |
2006-06-03 | CVE-2006-2805 | SQL Injection vulnerability in Jelsoft Vbulletin 3.0.10 SQL injection vulnerability in VBulletin 3.0.10 allows remote attackers to execute arbitrary SQL commands via the featureid parameter. | 5.0 |
2006-05-12 | CVE-2006-2335 | Remote Security vulnerability in Jelsoft Vbulletin 3.5.8 Jelsoft vBulletin accepts uploads of Cascading Style Sheets (CSS) and processes them in a way that allows remote authenticated administrators to gain shell access by uploading a CSS file that contains PHP code, then selecting the file via the style chooser, which causes the PHP code to be executed. | 6.5 |
2006-04-18 | CVE-2006-1816 | Remote Security vulnerability in Vbulletin 3.5.1/3.5.2/3.5.4 PHP remote file inclusion vulnerability in VBulletin 3.5.1, 3.5.2, and 3.5.4 allows remote attackers to execute arbitrary code via a URL in the systempath parameter to (1) ImpExModule.php, (2) ImpExController.php, and (3) ImpExDisplay.php. | 5.0 |
2006-03-07 | CVE-2006-1040 | HTML Injection vulnerability in Jelsoft Vbulletin 3.0.12/3.5.3 Cross-site scripting (XSS) vulnerability in vBulletin 3.0.12 and 3.5.3 allows remote attackers to inject arbitrary web script or HTML via the email field, which is injected in profile.php but not sanitized in sendmsg.php. network jelsoft | 4.3 |
2006-01-04 | CVE-2006-0080 | HTML Injection vulnerability in Jelsoft Vbulletin 3.5.2 Cross-site scripting (XSS) vulnerability in vBulletin 3.5.2, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the title of an event, which is not properly filtered by (1) calendar.php and (2) reminder.php. network jelsoft | 4.3 |
2005-12-31 | CVE-2005-4621 | Cross-Site Scripting vulnerability in VBulletin Cross-site scripting (XSS) vulnerability in the editavatar page in vBulletin 3.5.1 allows remote attackers to inject arbitrary web script or HTML via a URL in the remote avatar url field, in which the URL generates a parsing error, and possibly requiring a trailing extension such as .jpg. network jelsoft | 4.3 |
2005-09-21 | CVE-2005-3025 | Cross-Site Scripting vulnerability in vBulletin Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the loc parameter to (1) modcp/index.php or (2) admincp/index.php, or the ip parameter to (3) modcp/user.php or (4) admincp/usertitle.php. network jelsoft | 4.3 |
2005-09-21 | CVE-2005-3023 | Cross-Site Scripting vulnerability in vBulletin Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) announcement.php, (2) admincalendar.php, (3) bbcode.php, (4) cronadmin.php, (5) email.php, (6) faq.php, (7) forum.php, (8) image.php, (9) language.php, (10) ranks.php, (11) replacement.php, (12) replacement.php, (13) template.php, (14) template.php, (15) usergroup.php, or (16) usertitle.php. network jelsoft | 4.3 |