Show filters
100 Total Results
Displaying 91-100 of 100
Sort by:
Attacker Value
Unknown
CVE-2004-0620
Disclosure Date: December 06, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in (1) newreply.php or (2) newthread.php in vBulletin 3.0.1 allows remote attackers to inject arbitrary HTML or script as other users via the Edit-panel.
0
Attacker Value
Unknown
CVE-2004-0091
Disclosure Date: February 17, 2004 (last updated February 22, 2025)
NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter. NOTE: the vendor has disputed this issue, saying "There is no hidden field called 'reg_site', nor any $reg_site variable anywhere in the vBulletin 2 or vBulletin 3 source code or templates, nor has it ever existed. We can only assume that this vulnerability was found in a site running code modified from that supplied by Jelsoft.
0
Attacker Value
Unknown
CVE-2004-0036
Disclosure Date: January 20, 2004 (last updated February 22, 2025)
SQL injection vulnerability in calendar.php for vBulletin Forum 2.3.x before 2.3.4 allows remote attackers to steal sensitive information via the eventid parameter.
0
Attacker Value
Unknown
CVE-2003-0295
Disclosure Date: June 16, 2003 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in private.php for vBulletin 3.0.0 Beta 2 allows remote attackers to inject arbitrary web script and HTML via the "Preview Message" capability.
0
Attacker Value
Unknown
CVE-2002-1679
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 2.2.0 allows remote attackers to execute arbitrary script as other users by injecting script into a bulletin board message.
0
Attacker Value
Unknown
CVE-2002-1660
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command parameter.
0
Attacker Value
Unknown
CVE-2002-1678
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in memberlist.php in Jelsoft vBulletin 2.0 rc 2 through 2.2.4 allows remote attackers to steal authentication credentials by injecting script into $letterbits.
0
Attacker Value
Unknown
CVE-2002-2235
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
member2.php in vBulletin 2.2.9 and earlier does not properly restrict the $perpage variable to be an integer, which causes an error message to be reflected back to the user without quoting, which facilitates cross-site scripting (XSS) and possibly other attacks.
0
Attacker Value
Unknown
CVE-2002-1922
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in global.php in Jelsoft vBulletin 2.0.0 through 2.2.8 allows remote attackers to inject arbitrary web script or HTML via the (1) $scriptpath or (2) $url variables.
0
Attacker Value
Unknown
CVE-2001-0475
Disclosure Date: June 27, 2001 (last updated February 22, 2025)
index.php in Jelsoft vBulletin does not properly initialize a PHP variable that is used to store template information, which allows remote attackers to execute arbitrary PHP code via special characters in the templatecache parameter.
0