Jelsoft Vbulletin vulnerabilities
51 known vulnerabilities affecting jelsoft/vbulletin.
Total CVEs
51
CISA KEV
0
Public exploits
22
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH14MEDIUM32LOW4
Vulnerabilities
Page 3 of 3
CVE-2004-2076MEDIUMCVSS 4.3PoCv3.0.0_rc42004-12-31
CVE-2004-2076 [MEDIUM] CVE-2004-2076: Cross-site scripting (XSS) vulnerability in search.php for Jelsoft vBulletin 3.0.0 RC4 allows remote
Cross-site scripting (XSS) vulnerability in search.php for Jelsoft vBulletin 3.0.0 RC4 allows remote attackers to inject arbitrary web script or HTML via the query parameter.
nvd
CVE-2004-0620MEDIUMCVSS 4.3PoCv3.0.12004-12-06
CVE-2004-0620 [MEDIUM] CVE-2004-0620: Cross-site scripting (XSS) vulnerability in (1) newreply.php or (2) newthread.php in vBulletin 3.0.1
Cross-site scripting (XSS) vulnerability in (1) newreply.php or (2) newthread.php in vBulletin 3.0.1 allows remote attackers to inject arbitrary HTML or script as other users via the Edit-panel.
nvd
CVE-2004-0091MEDIUMCVSS 4.3v3.0_beta_22004-02-17
CVE-2004-0091 [MEDIUM] CVE-2004-0091: NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in regis
NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter. NOTE: the vendor has disputed this issue, saying "There is no hidden field called 'reg_site', nor any $reg_
nvd
CVE-2004-0036MEDIUMCVSS 5.0v2.3.02004-01-20
CVE-2004-0036 [MEDIUM] CVE-2004-0036: SQL injection vulnerability in calendar.php for vBulletin Forum 2.3.x before 2.3.4 allows remote att
SQL injection vulnerability in calendar.php for vBulletin Forum 2.3.x before 2.3.4 allows remote attackers to steal sensitive information via the eventid parameter.
nvd
CVE-2003-0295MEDIUMCVSS 6.8PoCv3.0.0_beta_22003-06-16
CVE-2003-0295 [MEDIUM] CVE-2003-0295: Cross-site scripting (XSS) vulnerability in private.php for vBulletin 3.0.0 Beta 2 allows remote att
Cross-site scripting (XSS) vulnerability in private.php for vBulletin 3.0.0 Beta 2 allows remote attackers to inject arbitrary web script and HTML via the "Preview Message" capability.
nvd
CVE-2002-1660HIGHCVSS 7.5PoC≤ 2.1.92002-12-31
CVE-2002-1660 [HIGH] CWE-78 CVE-2002-1660: calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via she
calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command parameter.
nvd
CVE-2002-1922MEDIUMCVSS 4.3PoCv2.0_rc2v2.0_rc3+9 more2002-12-31
CVE-2002-1922 [MEDIUM] CVE-2002-1922: Cross-site scripting (XSS) vulnerability in global.php in Jelsoft vBulletin 2.0.0 through 2.2.8 allo
Cross-site scripting (XSS) vulnerability in global.php in Jelsoft vBulletin 2.0.0 through 2.2.8 allows remote attackers to inject arbitrary web script or HTML via the (1) $scriptpath or (2) $url variables.
nvd
CVE-2002-1679MEDIUMCVSS 4.3v2.2.02002-12-31
CVE-2002-1679 [MEDIUM] CVE-2002-1679: Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 2.2.0 allows remote attackers to execu
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 2.2.0 allows remote attackers to execute arbitrary script as other users by injecting script into a bulletin board message.
nvd
CVE-2002-1678MEDIUMCVSS 4.3v2.0_rc2v2.0_rc3+5 more2002-12-31
CVE-2002-1678 [MEDIUM] CVE-2002-1678: Cross-site scripting (XSS) vulnerability in memberlist.php in Jelsoft vBulletin 2.0 rc 2 through 2.2
Cross-site scripting (XSS) vulnerability in memberlist.php in Jelsoft vBulletin 2.0 rc 2 through 2.2.4 allows remote attackers to steal authentication credentials by injecting script into $letterbits.
nvd
CVE-2002-2235MEDIUMCVSS 5.0PoCv2.0v2.0.1+12 more2002-12-31
CVE-2002-2235 [MEDIUM] CWE-189 CVE-2002-2235: member2.php in vBulletin 2.2.9 and earlier does not properly restrict the $perpage variable to be an
member2.php in vBulletin 2.2.9 and earlier does not properly restrict the $perpage variable to be an integer, which causes an error message to be reflected back to the user without quoting, which facilitates cross-site scripting (XSS) and possibly other attacks.
nvd
CVE-2001-0475HIGHCVSS 7.5≤ 1.1.5≤ 2.0_beta_22001-06-27
CVE-2001-0475 [HIGH] CVE-2001-0475: index.php in Jelsoft vBulletin does not properly initialize a PHP variable that is used to store tem
index.php in Jelsoft vBulletin does not properly initialize a PHP variable that is used to store template information, which allows remote attackers to execute arbitrary PHP code via special characters in the templatecache parameter.
nvd
← Previous3 / 3