Jelsoft
Jelsoft Vbulletin: vulnerabilidades y CVE
Jelsoft Vbulletin tiene 52 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE52
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2007-4453 | Media (4.3) | 1.0% | — | 21 ago 2007 | Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.6.8 allow remote attackers to inject arbitrary web code or HTML via the (1) s parameter to index.php, and the (2) q parameter to (a) faq.php, (b)… |
| CVE-2007-4120 | Alta (9.3) | 2.1% | — | 1 ago 2007 | Multiple PHP remote file inclusion vulnerabilities in Jelsoft vBulletin 3.6.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) classfile parameter to includes/functions.php, the (2) nextitem… |
| CVE-2007-3326 | Media (5.8) | 1.2% | — | 21 jun 2007 | Multiple directory traversal vulnerabilities in vBulletin 3.x.x allow remote attackers to redirect visitors to arbitrary local files via a .. (dot dot) in (1) the loc parameter to admincp/index.php and (2) the Hyperlink… |
| CVE-2007-2910 | Media (4.3) | 0.84% | — | 30 may 2007 | Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin before 3.6.7 PL1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the vb_367_xss_fix_plugin.xml update, a… |
| CVE-2007-2909 | Baja (3.5) | 0.69% | — | 30 may 2007 | Cross-site scripting (XSS) vulnerability in calendar.php in Jelsoft vBulletin 3.6.x before 3.6.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the… |
| CVE-2007-2908 | Media (4.3) | 1.8% | — | 30 may 2007 | Cross-site scripting (XSS) vulnerability in calendar.php in Jelsoft vBulletin before 3.6.6 allows remote attackers to inject arbitrary web script or HTML via the title field in a single add action. |
| CVE-2007-2912 | Media (5) | 1.2% | — | 30 may 2007 | Unspecified vulnerability in Jelsoft vBulletin before 3.6.6, when unauthenticated User Infraction Permissions is disabled, allows remote attackers to see the infraction "red flag" for a deleted user. |
| CVE-2007-2911 | Alta (8.5) | 1.3% | — | 30 may 2007 | SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin before 3.6.6 allows remote authenticated administrators to execute arbitrary SQL commands via the "Attached After" field… |
| CVE-2007-1573 | Media (6) | 0.90% | — | 21 mar 2007 | SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin 3.6.5 allows remote authenticated administrators to execute arbitrary SQL commands via the "Attached Before" field. |
| CVE-2007-1342 | Media (4.3) | 1.0% | — | 8 mar 2007 | Cross-site scripting (XSS) vulnerability in admincp/index.php in Jelsoft vBulletin 3.6.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the add rss url form. |
| CVE-2007-1292 | Alta (7.5) | 1.3% | — | 7 mar 2007 | SQL injection vulnerability in inlinemod.php in Jelsoft vBulletin before 3.5.8, and before 3.6.5 in the 3.6.x series, might allow remote authenticated users to execute arbitrary SQL commands via the postids parameter.… |
| CVE-2007-0869 | Media (4.3) | 1.1% | — | 9 feb 2007 | Cross-site scripting (XSS) vulnerability in the Attachment Manager (admincp/attachment.php) in Jelsoft vBulletin 3.6.4 allows remote attackers to inject arbitrary web script or HTML via the Extension field. NOTE: this… |
| CVE-2007-0830 | Baja (3.5) | 0.91% | — | 7 feb 2007 | Multiple cross-site scripting (XSS) vulnerabilities in the Admin Control Panel (AdminCP) in Jelsoft vBulletin 3.6.4 allow remote authenticated administrators to inject arbitrary web script or HTML via unspecified… |
| CVE-2006-6779 | Media (6.8) | 3.5% | — | 28 dic 2006 | Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin allows remote attackers to inject arbitrary web script or HTML via an SWF file that uses ActionScript to trigger execution of JavaScript. |
| CVE-2006-6040 | Media (6.8) | 2.2% | — | 22 nov 2006 | Multiple cross-site scripting (XSS) vulnerabilities in admincp/index.php in Jelsoft vBulletin 3.6.x allow remote attackers to inject arbitrary web script or HTML via (1) the prefs parameter in a buildnavprefs action or… |
| CVE-2006-5104 | Alta (7.5) | 1.1% | — | 3 oct 2006 | SQL injection vulnerability in global.php in Jelsoft vBulletin 2.x allows remote attackers to execute arbitrary SQL commands via the templatesused parameter. |
| CVE-2006-4271 | Alta (7.5) | 2.1% | — | 21 ago 2006 | PHP remote file inclusion vulnerability in install/upgrade_301.php in Jelsoft vBulletin 3.5.4 allows remote attackers to execute arbitrary PHP code via a URL in the step parameter. NOTE: the vendor has disputed this… |
| CVE-2006-4273 | Media (6.8) | 2.1% | — | 21 ago 2006 | Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 3.5.4 and 3.6.0 allows remote attackers to inject arbitrary web script or HTML by uploading an attachment with a .pdf extension that contains JavaScript,… |
| CVE-2006-4272 | Alta (7.5) | 1.5% | — | 21 ago 2006 | Jelsoft vBulletin 3.5.4 allows remote attackers to register multiple arbitrary users and cause a denial of service (resource consumption) via a large number of requests to register.php. NOTE: the vendor has disputed… |
| CVE-2006-3253 | Baja (2.6) | 2.0% | — | 28 jun 2006 | Cross-site scripting (XSS) vulnerability in member.php in vBulletin 3.5.x allows remote attackers to inject arbitrary web script or HTML via the u parameter. NOTE: the vendor has disputed this report, stating that they… |
| CVE-2006-2805 | Media (5) | 0.88% | — | 3 jun 2006 | SQL injection vulnerability in VBulletin 3.0.10 allows remote attackers to execute arbitrary SQL commands via the featureid parameter. |
| CVE-2006-2335 | Media (6.5) | 3.4% | — | 12 may 2006 | Jelsoft vBulletin accepts uploads of Cascading Style Sheets (CSS) and processes them in a way that allows remote authenticated administrators to gain shell access by uploading a CSS file that contains PHP code, then… |
| CVE-2006-2018 | Alta (7.5) | 1.2% | — | 25 abr 2006 | SQL injection vulnerability in calendar.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL commands via the eventid parameter. NOTE: the affected version has been disputed by the vendor. It appears… |
| CVE-2006-1816 | Media (5) | 2.9% | — | 18 abr 2006 | PHP remote file inclusion vulnerability in VBulletin 3.5.1, 3.5.2, and 3.5.4 allows remote attackers to execute arbitrary code via a URL in the systempath parameter to (1) ImpExModule.php, (2) ImpExController.php, and… |
| CVE-2006-1040 | Media (4.3) | 2.6% | — | 7 mar 2006 | Cross-site scripting (XSS) vulnerability in vBulletin 3.0.12 and 3.5.3 allows remote attackers to inject arbitrary web script or HTML via the email field, which is injected in profile.php but not sanitized in… |
| CVE-2006-0080 | Media (4.3) | 1.5% | — | 4 ene 2006 | Cross-site scripting (XSS) vulnerability in vBulletin 3.5.2, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the title of an event, which is not properly filtered by (1)… |
| CVE-2005-4621 | Media (4.3) | 1.2% | — | 31 dic 2005 | Cross-site scripting (XSS) vulnerability in the editavatar page in vBulletin 3.5.1 allows remote attackers to inject arbitrary web script or HTML via a URL in the remote avatar url field, in which the URL generates a… |
| CVE-2005-3021 | Baja (2.1) | 0.92% | — | 21 sept 2005 | image.php in vBulletin 3.0.9 and earlier allows remote attackers with access to the administrator panel to upload arbitrary files via the upload action. |
| CVE-2005-3020 | Media (4.3) | 1.8% | — | 21 sept 2005 | Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to css.php, (2) redirect parameter to index.php,… |
| CVE-2005-3024 | Alta (7.5) | 1.2% | — | 21 sept 2005 | Multiple SQL injection vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) announcement parameter to announcement.php, the (2) thread[forumid] or (3)… |