4.3
CVSSv2

CVE-2004-0620

Published: 06/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in (1) newreply.php or (2) newthread.php in vBulletin 3.0.1 allows remote malicious users to inject arbitrary HTML or script as other users via the Edit-panel.

Vulnerable Product Search on Vulmon Subscribe to Product

jelsoft vbulletin 3.0.1

Exploits

source: wwwsecurityfocuscom/bid/10602/info VBulletin is reported prone to an HTML injection vulnerability This issue affects the 'newreplyphp' and 'newthreadphp' scripts An attacker may exploit this issue by including hostile HTML and script code in fields that may be viewable by other users, potentially allowing for theft of cookie- ...