CVE-2004-0091Cross-site Scripting in Vbulletin

2 documents2 sources
Severity
4.3MEDIUMNVD
EPSS
0.4%
top 36.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 17
Latest updateApr 29

Description

NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter. NOTE: the vendor has disputed this issue, saying "There is no hidden field called 'reg_site', nor any $reg_site variable anywhere in the vBulletin 2 or vBulletin 3 source code or templates, nor has it ever existed. We can only assume that this vu

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDjelsoft/vbulletin3.0_beta_2

🔴Vulnerability Details

1
GHSA
GHSA-wm9h-x535-wxff: ** DISPUTED ** NOTE: this issue has been disputed by the vendor2022-04-29