Jelsoft Vbulletin vulnerabilities

51 known vulnerabilities affecting jelsoft/vbulletin.

Total CVEs
51
CISA KEV
0
Public exploits
22
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH14MEDIUM32LOW4

Vulnerabilities

Page 2 of 3
CVE-2006-2805MEDIUMCVSS 5.0PoCv3.0.102006-06-03
CVE-2006-2805 [MEDIUM] CVE-2006-2805: SQL injection vulnerability in VBulletin 3.0.10 allows remote attackers to execute arbitrary SQL com SQL injection vulnerability in VBulletin 3.0.10 allows remote attackers to execute arbitrary SQL commands via the featureid parameter.
nvd
CVE-2006-2335MEDIUMCVSS 6.5v3.5.82006-05-12
CVE-2006-2335 [MEDIUM] CVE-2006-2335: Jelsoft vBulletin accepts uploads of Cascading Style Sheets (CSS) and processes them in a way that a Jelsoft vBulletin accepts uploads of Cascading Style Sheets (CSS) and processes them in a way that allows remote authenticated administrators to gain shell access by uploading a CSS file that contains PHP code, then selecting the file via the style chooser, which causes the PHP code to be executed. NOTE: the vendor was unable to reproduce this issue in 3.5.x.
nvd
CVE-2006-2018HIGHCVSS 7.5v3.0v3.0.0+11 more2006-04-25
CVE-2006-2018 [HIGH] CVE-2006-2018: SQL injection vulnerability in calendar.php in vBulletin 3.0.x allows remote attackers to execute ar SQL injection vulnerability in calendar.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL commands via the eventid parameter. NOTE: the affected version has been disputed by the vendor. It appears that this is the same issue as CVE-2004-0036, which was fixed in 2.3.4.
nvd
CVE-2006-1816MEDIUMCVSS 5.0v3.5.1v3.5.2+1 more2006-04-18
CVE-2006-1816 [MEDIUM] CVE-2006-1816: PHP remote file inclusion vulnerability in VBulletin 3.5.1, 3.5.2, and 3.5.4 allows remote attackers PHP remote file inclusion vulnerability in VBulletin 3.5.1, 3.5.2, and 3.5.4 allows remote attackers to execute arbitrary code via a URL in the systempath parameter to (1) ImpExModule.php, (2) ImpExController.php, and (3) ImpExDisplay.php.
nvd
CVE-2006-1040MEDIUMCVSS 4.3PoCv3.0.12v3.5.32006-03-07
CVE-2006-1040 [MEDIUM] CVE-2006-1040: Cross-site scripting (XSS) vulnerability in vBulletin 3.0.12 and 3.5.3 allows remote attackers to in Cross-site scripting (XSS) vulnerability in vBulletin 3.0.12 and 3.5.3 allows remote attackers to inject arbitrary web script or HTML via the email field, which is injected in profile.php but not sanitized in sendmsg.php.
nvd
CVE-2006-0080MEDIUMCVSS 4.3v3.5.22006-01-04
CVE-2006-0080 [MEDIUM] CVE-2006-0080: Cross-site scripting (XSS) vulnerability in vBulletin 3.5.2, and possibly earlier versions, allows r Cross-site scripting (XSS) vulnerability in vBulletin 3.5.2, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the title of an event, which is not properly filtered by (1) calendar.php and (2) reminder.php.
nvd
CVE-2005-4621MEDIUMCVSS 4.3v1.0.1v2.0.3+36 more2005-12-31
CVE-2005-4621 [MEDIUM] CVE-2005-4621: Cross-site scripting (XSS) vulnerability in the editavatar page in vBulletin 3.5.1 allows remote att Cross-site scripting (XSS) vulnerability in the editavatar page in vBulletin 3.5.1 allows remote attackers to inject arbitrary web script or HTML via a URL in the remote avatar url field, in which the URL generates a parsing error, and possibly requiring a trailing extension such as .jpg.
nvd
CVE-2005-3019HIGHCVSS 7.5PoCv1.0.1v2.0.3+32 more2005-09-21
CVE-2005-3019 [HIGH] CVE-2005-3019: Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute a Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL commands via the (1) request parameter to joinrequests.php, (2) limitnumber or (3) limitstart to user.php, (4) usertitle.php, or (5) usertools.php.
nvd
CVE-2005-3022HIGHCVSS 7.5v1.0.1v2.0.3+33 more2005-09-21
CVE-2005-3022 [HIGH] CVE-2005-3022: Multiple SQL injection vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to exec Multiple SQL injection vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) announcement parameter to announcement.php, (2) userid parameter to user.php, (3) calendar parameter to admincalendar.php, (4) cronid parameter to cronlog.php, (5) usergroupid parameter to email.php, (6) help parameter to he
nvd
CVE-2005-3024HIGHCVSS 7.5v1.0.1v2.0.3+31 more2005-09-21
CVE-2005-3024 [HIGH] CVE-2005-3024: Multiple SQL injection vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to exec Multiple SQL injection vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) announcement parameter to announcement.php, the (2) thread[forumid] or (3) criteria parameters to thread.php, (4) userid parameter to user.php, the (5) calendarcustomfieldid, (6) calendarid, (7) moderatorid, (8) holidayid, (
nvd
CVE-2005-3025MEDIUMCVSS 4.3v1.0.1v2.0.3+31 more2005-09-21
CVE-2005-3025 [MEDIUM] CVE-2005-3025: Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.7 and earlier allow remote atta Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the loc parameter to (1) modcp/index.php or (2) admincp/index.php, or the ip parameter to (3) modcp/user.php or (4) admincp/usertitle.php.
nvd
CVE-2005-3020MEDIUMCVSS 4.3PoCv1.0.1v2.0.3+33 more2005-09-21
CVE-2005-3020 [MEDIUM] CVE-2005-3020: Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to css.php, (2) redirect parameter to index.php, (3) email parameter to user.php, (4) goto parameter to language.php, (5) orderby parameter to modlog.php, and the (6) hex, (7) rgb, or (8) expan
nvd
CVE-2005-3023MEDIUMCVSS 4.3v1.0.1v2.0.3+33 more2005-09-21
CVE-2005-3023 [MEDIUM] CVE-2005-3023: Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.9 and earlier allow remote atta Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) announcement.php, (2) admincalendar.php, (3) bbcode.php, (4) cronadmin.php, (5) email.php, (6) faq.php, (7) forum.php, (8) image.php, (9) language.php, (10) ranks.php, (11) replacement.ph
nvd
CVE-2005-3021LOWCVSS 2.1v1.0.1v2.0.3+33 more2005-09-21
CVE-2005-3021 [LOW] CVE-2005-3021: image.php in vBulletin 3.0.9 and earlier allows remote attackers with access to the administrator pa image.php in vBulletin 3.0.9 and earlier allows remote attackers with access to the administrator panel to upload arbitrary files via the upload action.
nvd
CVE-2005-0429MEDIUMCVSS 5.0PoCv3.0v3.0.1+3 more2005-05-02
CVE-2005-0429 [MEDIUM] CVE-2005-0429: Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showfor Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showforumusers is enabled, allows remote attackers to execute inject arbitrary PHP commands via the comma parameter.
nvd
CVE-2005-0511HIGHCVSS 7.5PoCv2.0v2.0.1+27 more2005-02-21
CVE-2005-0511 [HIGH] CVE-2005-0511: misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allo misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.
nvd
CVE-2004-1515HIGHCVSS 7.5PoCv3.0.0v3.0.0_beta_2+9 more2004-12-31
CVE-2004-1515 [HIGH] CVE-2004-1515: SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote at SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL statements via the fsel parameter, as demonstrated using last.php.
nvd
CVE-2004-2695HIGHCVSS 7.5v3.0v3.0.1+9 more2004-12-31
CVE-2004-2695 [HIGH] CWE-89 CVE-2004-2695: SQL injection vulnerability in the Authorize.net callback code (subscriptions/authorize.php) in Jels SQL injection vulnerability in the Authorize.net callback code (subscriptions/authorize.php) in Jelsoft vBulletin 3.0 through 3.0.3 allows remote attackers to execute arbitrary SQL statements via the x_invoice_num parameter. NOTE: this issue might be related to CVE-2006-4267.
nvd
CVE-2004-1823MEDIUMCVSS 4.3PoCv3.0.0v3.0.0_can42004-12-31
CVE-2004-1823 [MEDIUM] CVE-2004-1823: Multiple cross-site scripting (XSS) vulnerabilities in Jelsoft vBulletin 2.0 beta 3 through 3.0 can4 Multiple cross-site scripting (XSS) vulnerabilities in Jelsoft vBulletin 2.0 beta 3 through 3.0 can4 allows remote attackers to inject arbitrary web script or HTML via the (1) page parameter to showthread.php or (2) order parameter to forumdisplay.php.
nvd
CVE-2004-2288MEDIUMCVSS 4.3PoCv1.0.1v2.0.3+23 more2004-12-31
CVE-2004-2288 [MEDIUM] CVE-2004-2288: Cross-site scripting (XSS) vulnerability in index.php in Jelsoft vBulletin allows remote attackers t Cross-site scripting (XSS) vulnerability in index.php in Jelsoft vBulletin allows remote attackers to spoof parts of a website via the loc parameter.
nvd