Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
jelsoft vbulletin vulnerabilities and exploits
(subscribe to this query)
383
VMScore
CVE-2007-2910
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin prior to 3.6.7 PL1 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors, related to the vb_367_xss_fix_plugin.xml update, a related issue to CVE-2007-2909.
Jelsoft Vbulletin
445
VMScore
CVE-2007-2912
Unspecified vulnerability in Jelsoft vBulletin prior to 3.6.6, when unauthenticated User Infraction Permissions is disabled, allows remote malicious users to see the infraction "red flag" for a deleted user.
Jelsoft Vbulletin
668
VMScore
CVE-2001-0475
index.php in Jelsoft vBulletin does not properly initialize a PHP variable that is used to store template information, which allows remote malicious users to execute arbitrary PHP code via special characters in the templatecache parameter.
Jelsoft Vbulletin
756
VMScore
CVE-2007-2911
SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin prior to 3.6.6 allows remote authenticated administrators to execute arbitrary SQL commands via the "Attached After" field (GPC['search']['datelineafter'] variable), a related...
Jelsoft Vbulletin
435
VMScore
CVE-2007-2908
Cross-site scripting (XSS) vulnerability in calendar.php in Jelsoft vBulletin prior to 3.6.6 allows remote malicious users to inject arbitrary web script or HTML via the title field in a single add action.
Jelsoft Vbulletin
1 EDB exploit
578
VMScore
CVE-2006-2335
Jelsoft vBulletin accepts uploads of Cascading Style Sheets (CSS) and processes them in a way that allows remote authenticated administrators to gain shell access by uploading a CSS file that contains PHP code, then selecting the file via the style chooser, which causes the PHP c...
Jelsoft Vbulletin 3.5.8
505
VMScore
CVE-2006-2805
SQL injection vulnerability in VBulletin 3.0.10 allows remote malicious users to execute arbitrary SQL commands via the featureid parameter.
Jelsoft Vbulletin 3.0.10
1 EDB exploit
383
VMScore
CVE-2007-4453
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.6.8 allow remote malicious users to inject arbitrary web code or HTML via the (1) s parameter to index.php, and the (2) q parameter to (a) faq.php, (b) member.php, (c) memberlist.php, (d) calendar.php, (e) search....
Jelsoft Vbulletin 3.6.8
445
VMScore
CVE-2004-0036
SQL injection vulnerability in calendar.php for vBulletin Forum 2.3.x prior to 2.3.4 allows remote malicious users to steal sensitive information via the eventid parameter.
Jelsoft Vbulletin 2.3.0
383
VMScore
CVE-2004-0091
NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote malicious users to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter. NOTE: the vendor has...
Jelsoft Vbulletin 3.0 Beta 2
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »