7.5
CVSSv2

CVE-2005-3019

Published: 21/09/2005 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 770
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in vBulletin prior to 3.0.9 allow remote malicious users to execute arbitrary SQL commands via the (1) request parameter to joinrequests.php, (2) limitnumber or (3) limitstart to user.php, (4) usertitle.php, or (5) usertools.php.

Vulnerable Product Search on Vulmon Subscribe to Product

jelsoft vbulletin 1.0.1

jelsoft vbulletin 2.2.3

jelsoft vbulletin 2.2.4

jelsoft vbulletin 2.3.2

jelsoft vbulletin 2.3.3

jelsoft vbulletin 3.0.6

jelsoft vbulletin 3.0.7

jelsoft vbulletin 3.0_beta_7

jelsoft vbulletin 3.0_gamma

jelsoft vbulletin 2.0.3

jelsoft vbulletin 2.0_rc2

jelsoft vbulletin 2.2.5

jelsoft vbulletin 2.2.6

jelsoft vbulletin 2.3.4

jelsoft vbulletin 3.0

jelsoft vbulletin 3.0.1

jelsoft vbulletin 3.0.8

jelsoft vbulletin 3.0_beta_2

jelsoft vbulletin 2.2.1

jelsoft vbulletin 2.2.2

jelsoft vbulletin 2.2.9

jelsoft vbulletin 2.3.0

jelsoft vbulletin 3.0.4

jelsoft vbulletin 3.0.5

jelsoft vbulletin 3.0_beta_5

jelsoft vbulletin 3.0_beta_6

jelsoft vbulletin 2.0_rc3

jelsoft vbulletin 2.2.0

jelsoft vbulletin 2.2.7

jelsoft vbulletin 2.2.8

jelsoft vbulletin 3.0.2

jelsoft vbulletin 3.0.3

jelsoft vbulletin 3.0_beta_3

jelsoft vbulletin 3.0_beta_4

Exploits

source: wwwsecurityfocuscom/bid/14872/info vBulletin is prone to multiple SQL injection vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries Successful exploitation could result in a compromise of the application, disclosure or modification of d ...
source: wwwsecurityfocuscom/bid/14872/info vBulletin is prone to multiple SQL injection vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries Successful exploitation could result in a compromise of the application, disclosure or modification of dat ...
source: wwwsecurityfocuscom/bid/14872/info vBulletin is prone to multiple SQL injection vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries Successful exploitation could result in a compromise of the application, disclosure or modification of data, ...
source: wwwsecurityfocuscom/bid/14872/info vBulletin is prone to multiple SQL injection vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input before using it in SQL queries Successful exploitation could result in a compromise of the application, disclosure or modification of ...