4.3
CVSSv2

CVE-2003-1031

Published: 17/02/2004 Updated: 05/09/2008
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in register.php for vBulletin 3.0 Beta 2 allows remote malicious users to inject arbitrary HTML or web script via optional fields such as (1) "Interests-Hobbies", (2) "Biography", or (3) "Occupation."

Vulnerable Product Search on Vulmon Subscribe to Product

Exploits

source: wwwsecurityfocuscom/bid/8354/info vBulletin may be prone to an HTML injection vulnerability This issue is exposed through inadequate sanitization of user input for certain fields within the registerphp script An attacker may exploit this issue by including hostile HTML and script code in fields that may be displayed in posts to ...