Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
jelsoft vbulletin vulnerabilities and exploits
(subscribe to this query)
8.5
CVSSv2
CVE-2007-2911
SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin prior to 3.6.6 allows remote authenticated administrators to execute arbitrary SQL commands via the "Attached After" field (GPC['search']['datelineafter'] variable), a related...
Jelsoft Vbulletin
5
CVSSv2
CVE-2007-2912
Unspecified vulnerability in Jelsoft vBulletin prior to 3.6.6, when unauthenticated User Infraction Permissions is disabled, allows remote malicious users to see the infraction "red flag" for a deleted user.
Jelsoft Vbulletin
4.3
CVSSv2
CVE-2007-1342
Cross-site scripting (XSS) vulnerability in admincp/index.php in Jelsoft vBulletin 3.6.5 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the add rss url form.
Jelsoft Vbulletin
7.5
CVSSv2
CVE-2002-1660
calendar.php in vBulletin prior to 2.2.0 allows remote malicious users to execute arbitrary commands via shell metacharacters in the command parameter.
Jelsoft Vbulletin
1 EDB exploit
7.5
CVSSv2
CVE-2001-0475
index.php in Jelsoft vBulletin does not properly initialize a PHP variable that is used to store template information, which allows remote malicious users to execute arbitrary PHP code via special characters in the templatecache parameter.
Jelsoft Vbulletin
9.3
CVSSv2
CVE-2007-4120
Multiple PHP remote file inclusion vulnerabilities in Jelsoft vBulletin 3.6.5 allow remote malicious users to execute arbitrary PHP code via a URL in the (1) classfile parameter to includes/functions.php, the (2) nextitem parameter to includes/functions_cron.php, and the (3) spec...
Jelsoft Vbulletin 3.6.5
6.5
CVSSv2
CVE-2006-2335
Jelsoft vBulletin accepts uploads of Cascading Style Sheets (CSS) and processes them in a way that allows remote authenticated administrators to gain shell access by uploading a CSS file that contains PHP code, then selecting the file via the style chooser, which causes the PHP c...
Jelsoft Vbulletin 3.5.8
7.5
CVSSv2
CVE-2006-4271
PHP remote file inclusion vulnerability in install/upgrade_301.php in Jelsoft vBulletin 3.5.4 allows remote malicious users to execute arbitrary PHP code via a URL in the step parameter. NOTE: the vendor has disputed this vulnerability, saying "The default vBulletin requires...
Jelsoft Vbulletin 3.5.4
7.5
CVSSv2
CVE-2006-4272
Jelsoft vBulletin 3.5.4 allows remote malicious users to register multiple arbitrary users and cause a denial of service (resource consumption) via a large number of requests to register.php. NOTE: the vendor has disputed this vulnerability, stating "If you have the CAPTCHA ...
Jelsoft Vbulletin 3.5.4
4.3
CVSSv2
CVE-2006-0080
Cross-site scripting (XSS) vulnerability in vBulletin 3.5.2, and possibly earlier versions, allows remote malicious users to inject arbitrary web script or HTML via the title of an event, which is not properly filtered by (1) calendar.php and (2) reminder.php.
Jelsoft Vbulletin 3.5.2
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-30078
CVE-2024-37896
code injection
CVE-2024-3080
CVE-2024-5172
cross-site request forgery
CVE-2024-6111
firmware
CVE-2024-38504
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »