Vulnerabilities > Vbulletin > Vbulletin > 4.2.1

DATE CVE VULNERABILITY TITLE RISK
2014-11-06 CVE-2014-8670 Unspecified vulnerability in Vbulletin 4.2.1
Open redirect vulnerability in go.php in vBulletin 4.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.
network
vbulletin
5.8
2014-10-15 CVE-2014-2022 SQL Injection vulnerability in Vbulletin
SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and earlier allows remote authenticated users to execute arbitrary SQL commands via the conceptid argument in an xmlrpc API request.
network
high complexity
vbulletin CWE-89
7.1