Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
vbulletin vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2007-1342
Cross-site scripting (XSS) vulnerability in admincp/index.php in Jelsoft vBulletin 3.6.5 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the add rss url form.
Jelsoft Vbulletin
7.5
CVSSv2
CVE-2002-1660
calendar.php in vBulletin prior to 2.2.0 allows remote malicious users to execute arbitrary commands via shell metacharacters in the command parameter.
Jelsoft Vbulletin
1 EDB exploit
7.5
CVSSv2
CVE-2001-0475
index.php in Jelsoft vBulletin does not properly initialize a PHP variable that is used to store template information, which allows remote malicious users to execute arbitrary PHP code via special characters in the templatecache parameter.
Jelsoft Vbulletin
5
CVSSv2
CVE-2006-2805
SQL injection vulnerability in VBulletin 3.0.10 allows remote malicious users to execute arbitrary SQL commands via the featureid parameter.
Jelsoft Vbulletin 3.0.10
1 EDB exploit
7.5
CVSSv2
CVE-2006-4272
Jelsoft vBulletin 3.5.4 allows remote malicious users to register multiple arbitrary users and cause a denial of service (resource consumption) via a large number of requests to register.php. NOTE: the vendor has disputed this vulnerability, stating "If you have the CAPTCHA ...
Jelsoft Vbulletin 3.5.4
6.8
CVSSv2
CVE-2003-0295
Cross-site scripting (XSS) vulnerability in private.php for vBulletin 3.0.0 Beta 2 allows remote malicious users to inject arbitrary web script and HTML via the "Preview Message" capability.
Jelsoft Vbulletin 3.0.0 Beta 2
1 EDB exploit
4.3
CVSSv2
CVE-2002-1679
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 2.2.0 allows remote malicious users to execute arbitrary script as other users by injecting script into a bulletin board message.
Jelsoft Vbulletin 2.2.0
4.3
CVSSv2
CVE-2004-0091
NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote malicious users to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter. NOTE: the vendor has...
Jelsoft Vbulletin 3.0 Beta 2
7.5
CVSSv2
CVE-2006-4271
PHP remote file inclusion vulnerability in install/upgrade_301.php in Jelsoft vBulletin 3.5.4 allows remote malicious users to execute arbitrary PHP code via a URL in the step parameter. NOTE: the vendor has disputed this vulnerability, saying "The default vBulletin requires...
Jelsoft Vbulletin 3.5.4
7.5
CVSSv2
CVE-2008-4706
SQL injection vulnerability in VBGooglemap Hotspot Edition 1.0.3, a vBulletin module, allows remote malicious users to execute arbitrary SQL commands via the mapid parameter in a showdetails action to (1) vbgooglemaphse.php and (2) mapa.php.
Vbulletin Vbgooglemap 1.0.3
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5324
path traversal
CVE-2024-4743
CVE-2024-5184
TCP
CVE-2024-27822
code injection
CVE-2024-28995
CVE-2023-20938
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9
10
NEXT »