3.5
CVSSv2

CVE-2014-2021

Published: 25/10/2014 Updated: 29/08/2017
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in admincp/apilog.php in vBulletin 4.2.2 and previous versions, and 5.0.x up to and including 5.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted XMLRPC API request, as demonstrated using the client name.

Vulnerable Product Search on Vulmon Subscribe to Product

vbulletin vbulletin 5.0.4

vbulletin vbulletin 5.0.3

vbulletin vbulletin

vbulletin vbulletin 5.0.5

vbulletin vbulletin 5.0.0

vbulletin vbulletin 5.0.2

vbulletin vbulletin 5.0.1

Exploits

CVE-2014-2021 - vBulletin 5x/4x - persistent XSS in AdminCP/ApiLog via xmlrpc API (post-auth) ================================================================================================ Overview -------- date : 10/12/2014 cvss : 46 (AV:N/AC:H/Au:S/C:P/I:P/A:P) base cwe : 79 vendor : vBulletin Solutions product : vB ...
vBulletin versions 5x and 4x suffer from a persistent cross site scripting vulnerability ...