vBulletin 1.0/2.x/3.0 - 'index.php' User Interface Spoofing

Related Vulnerabilities: CVE-2004-2288  
Publish Date: 17 May 2004
Author: p0rk
                							

                source: http://www.securityfocus.com/bid/10362/info

A weakness has been reported to exist in the VBulletin software that may allow an attacker to spoof parts of the VBulletin interface. The issue exists due to improper validation of user-supplied data.

Remote attackers may potentially exploit this issue, by convincing a VBulletin administrator to follow a specially crafted URI. The URI would contain a URI to a remote attacker owned HTML page as a value for the affected parameter of the 'index.php' script. If the administrator were to follow this link, part of the VBulletin user interface may be spoofed by the attacker.

http://forums.example.com/admincp/index.php?loc=http://www.example.com