Jelsoft Vbulletin vulnerabilities
51 known vulnerabilities affecting jelsoft/vbulletin.
Total CVEs
51
CISA KEV
0
Public exploits
22
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH14MEDIUM32LOW4
Vulnerabilities
Page 2 of 3
CVE-2006-2805MEDIUMCVSS 5.0PoCv3.0.102006-06-03
CVE-2006-2805 [MEDIUM] CVE-2006-2805: SQL injection vulnerability in VBulletin 3.0.10 allows remote attackers to execute arbitrary SQL com
SQL injection vulnerability in VBulletin 3.0.10 allows remote attackers to execute arbitrary SQL commands via the featureid parameter.
nvd
CVE-2006-2335MEDIUMCVSS 6.5v3.5.82006-05-12
CVE-2006-2335 [MEDIUM] CVE-2006-2335: Jelsoft vBulletin accepts uploads of Cascading Style Sheets (CSS) and processes them in a way that a
Jelsoft vBulletin accepts uploads of Cascading Style Sheets (CSS) and processes them in a way that allows remote authenticated administrators to gain shell access by uploading a CSS file that contains PHP code, then selecting the file via the style chooser, which causes the PHP code to be executed. NOTE: the vendor was unable to reproduce this issue in 3.5.x.
nvd
CVE-2006-2018HIGHCVSS 7.5v3.0v3.0.0+11 more2006-04-25
CVE-2006-2018 [HIGH] CVE-2006-2018: SQL injection vulnerability in calendar.php in vBulletin 3.0.x allows remote attackers to execute ar
SQL injection vulnerability in calendar.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL commands via the eventid parameter. NOTE: the affected version has been disputed by the vendor. It appears that this is the same issue as CVE-2004-0036, which was fixed in 2.3.4.
nvd
CVE-2006-1816MEDIUMCVSS 5.0v3.5.1v3.5.2+1 more2006-04-18
CVE-2006-1816 [MEDIUM] CVE-2006-1816: PHP remote file inclusion vulnerability in VBulletin 3.5.1, 3.5.2, and 3.5.4 allows remote attackers
PHP remote file inclusion vulnerability in VBulletin 3.5.1, 3.5.2, and 3.5.4 allows remote attackers to execute arbitrary code via a URL in the systempath parameter to (1) ImpExModule.php, (2) ImpExController.php, and (3) ImpExDisplay.php.
nvd
CVE-2006-1040MEDIUMCVSS 4.3PoCv3.0.12v3.5.32006-03-07
CVE-2006-1040 [MEDIUM] CVE-2006-1040: Cross-site scripting (XSS) vulnerability in vBulletin 3.0.12 and 3.5.3 allows remote attackers to in
Cross-site scripting (XSS) vulnerability in vBulletin 3.0.12 and 3.5.3 allows remote attackers to inject arbitrary web script or HTML via the email field, which is injected in profile.php but not sanitized in sendmsg.php.
nvd
CVE-2006-0080MEDIUMCVSS 4.3v3.5.22006-01-04
CVE-2006-0080 [MEDIUM] CVE-2006-0080: Cross-site scripting (XSS) vulnerability in vBulletin 3.5.2, and possibly earlier versions, allows r
Cross-site scripting (XSS) vulnerability in vBulletin 3.5.2, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the title of an event, which is not properly filtered by (1) calendar.php and (2) reminder.php.
nvd
CVE-2005-4621MEDIUMCVSS 4.3v1.0.1v2.0.3+36 more2005-12-31
CVE-2005-4621 [MEDIUM] CVE-2005-4621: Cross-site scripting (XSS) vulnerability in the editavatar page in vBulletin 3.5.1 allows remote att
Cross-site scripting (XSS) vulnerability in the editavatar page in vBulletin 3.5.1 allows remote attackers to inject arbitrary web script or HTML via a URL in the remote avatar url field, in which the URL generates a parsing error, and possibly requiring a trailing extension such as .jpg.
nvd
CVE-2005-3019HIGHCVSS 7.5PoCv1.0.1v2.0.3+32 more2005-09-21
CVE-2005-3019 [HIGH] CVE-2005-3019: Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute a
Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL commands via the (1) request parameter to joinrequests.php, (2) limitnumber or (3) limitstart to user.php, (4) usertitle.php, or (5) usertools.php.
nvd
CVE-2005-3022HIGHCVSS 7.5v1.0.1v2.0.3+33 more2005-09-21
CVE-2005-3022 [HIGH] CVE-2005-3022: Multiple SQL injection vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to exec
Multiple SQL injection vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) announcement parameter to announcement.php, (2) userid parameter to user.php, (3) calendar parameter to admincalendar.php, (4) cronid parameter to cronlog.php, (5) usergroupid parameter to email.php, (6) help parameter to he
nvd
CVE-2005-3024HIGHCVSS 7.5v1.0.1v2.0.3+31 more2005-09-21
CVE-2005-3024 [HIGH] CVE-2005-3024: Multiple SQL injection vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to exec
Multiple SQL injection vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) announcement parameter to announcement.php, the (2) thread[forumid] or (3) criteria parameters to thread.php, (4) userid parameter to user.php, the (5) calendarcustomfieldid, (6) calendarid, (7) moderatorid, (8) holidayid, (
nvd
CVE-2005-3025MEDIUMCVSS 4.3v1.0.1v2.0.3+31 more2005-09-21
CVE-2005-3025 [MEDIUM] CVE-2005-3025: Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.7 and earlier allow remote atta
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the loc parameter to (1) modcp/index.php or (2) admincp/index.php, or the ip parameter to (3) modcp/user.php or (4) admincp/usertitle.php.
nvd
CVE-2005-3020MEDIUMCVSS 4.3PoCv1.0.1v2.0.3+33 more2005-09-21
CVE-2005-3020 [MEDIUM] CVE-2005-3020: Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to css.php, (2) redirect parameter to index.php, (3) email parameter to user.php, (4) goto parameter to language.php, (5) orderby parameter to modlog.php, and the (6) hex, (7) rgb, or (8) expan
nvd
CVE-2005-3023MEDIUMCVSS 4.3v1.0.1v2.0.3+33 more2005-09-21
CVE-2005-3023 [MEDIUM] CVE-2005-3023: Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.9 and earlier allow remote atta
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) announcement.php, (2) admincalendar.php, (3) bbcode.php, (4) cronadmin.php, (5) email.php, (6) faq.php, (7) forum.php, (8) image.php, (9) language.php, (10) ranks.php, (11) replacement.ph
nvd
CVE-2005-3021LOWCVSS 2.1v1.0.1v2.0.3+33 more2005-09-21
CVE-2005-3021 [LOW] CVE-2005-3021: image.php in vBulletin 3.0.9 and earlier allows remote attackers with access to the administrator pa
image.php in vBulletin 3.0.9 and earlier allows remote attackers with access to the administrator panel to upload arbitrary files via the upload action.
nvd
CVE-2005-0429MEDIUMCVSS 5.0PoCv3.0v3.0.1+3 more2005-05-02
CVE-2005-0429 [MEDIUM] CVE-2005-0429: Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showfor
Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showforumusers is enabled, allows remote attackers to execute inject arbitrary PHP commands via the comma parameter.
nvd
CVE-2005-0511HIGHCVSS 7.5PoCv2.0v2.0.1+27 more2005-02-21
CVE-2005-0511 [HIGH] CVE-2005-0511: misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allo
misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.
nvd
CVE-2004-1515HIGHCVSS 7.5PoCv3.0.0v3.0.0_beta_2+9 more2004-12-31
CVE-2004-1515 [HIGH] CVE-2004-1515: SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote at
SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL statements via the fsel parameter, as demonstrated using last.php.
nvd
CVE-2004-2695HIGHCVSS 7.5v3.0v3.0.1+9 more2004-12-31
CVE-2004-2695 [HIGH] CWE-89 CVE-2004-2695: SQL injection vulnerability in the Authorize.net callback code (subscriptions/authorize.php) in Jels
SQL injection vulnerability in the Authorize.net callback code (subscriptions/authorize.php) in Jelsoft vBulletin 3.0 through 3.0.3 allows remote attackers to execute arbitrary SQL statements via the x_invoice_num parameter. NOTE: this issue might be related to CVE-2006-4267.
nvd
CVE-2004-1823MEDIUMCVSS 4.3PoCv3.0.0v3.0.0_can42004-12-31
CVE-2004-1823 [MEDIUM] CVE-2004-1823: Multiple cross-site scripting (XSS) vulnerabilities in Jelsoft vBulletin 2.0 beta 3 through 3.0 can4
Multiple cross-site scripting (XSS) vulnerabilities in Jelsoft vBulletin 2.0 beta 3 through 3.0 can4 allows remote attackers to inject arbitrary web script or HTML via the (1) page parameter to showthread.php or (2) order parameter to forumdisplay.php.
nvd
CVE-2004-2288MEDIUMCVSS 4.3PoCv1.0.1v2.0.3+23 more2004-12-31
CVE-2004-2288 [MEDIUM] CVE-2004-2288: Cross-site scripting (XSS) vulnerability in index.php in Jelsoft vBulletin allows remote attackers t
Cross-site scripting (XSS) vulnerability in index.php in Jelsoft vBulletin allows remote attackers to spoof parts of a website via the loc parameter.
nvd