« Volver al listado

CVE-2005-3024

Estado: ModificadaAlta (7.5)—

Multiple SQL injection vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) announcement parameter to announcement.php, the (2) thread[forumid] or (3) criteria parameters to thread.php, (4) userid parameter to user.php, the (5) calendarcustomfieldid, (6) calendarid, (7) moderatorid, (8) holidayid, (9) calendarmoderatorid, or (10) calendar[0] parameters to admincalendar.php, (11) the cronid parameter to cronlog.php, (12) user[usergroupid][0] parameter to email.php, (13) help[0] parameter to help.php, the (14) limitnumber or (15) limitstart parameter to user.php, the (16) usertitleid or (17) ids parameters to usertitle.php, (18) rvt[0] parameter to language.php, (19) keep[0] parameter to phrase.php, (20) dostyleid parameter to template.php, (21) thread[forumid] parameter to thread.php, or (22) usertools.php.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2005-3024",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2005-09-21T22:03:00.000",
  "references": [
    {
      "url": "http://marc.info/?l=bugtraq&m=112732980702939&w=2",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://morph3us.org/advisories/20050917-vbulletin-3.0.7.txt",
      "tags": [
        "Exploit",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=112732980702939&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://morph3us.org/advisories/20050917-vbulletin-3.0.7.txt",
      "tags": [
        "Exploit",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple SQL injection vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) announcement parameter to announcement.php, the (2) thread[forumid] or (3) criteria parameters to thread.php, (4) userid parameter to user.php, the (5) calendarcustomfieldid, (6) calendarid, (7) moderatorid, (8) holidayid, (9) calendarmoderatorid, or (10) calendar[0] parameters to admincalendar.php, (11) the cronid parameter to cronlog.php, (12) user[usergroupid][0] parameter to email.php, (13) help[0] parameter to help.php, the (14) limitnumber or (15) limitstart parameter to user.php, the (16) usertitleid or (17) ids parameters to usertitle.php, (18) rvt[0] parameter to language.php, (19) keep[0] parameter to phrase.php, (20) dostyleid parameter to template.php, (21) thread[forumid] parameter to thread.php, or (22) usertools.php."
    }
  ],
  "lastModified": "2026-06-16T22:16:06.540",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:1.0.1:*:lite:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "70BC7FDF-AEAD-4BCA-AB0B-36F62D3D92A1"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:2.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CAC28EB5-343A-4B55-8ECE-8C46D304A1BC"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:2.0_rc2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7C3499B6-7DC8-4DE5-80EB-1EEA3307ABA8"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:2.0_rc3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B53F61D2-5FD2-4625-A9FB-8E0258924BAC"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:2.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FEA26ED0-6DF8-4730-AE19-E8F4AB9AC906"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:2.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "306C6BDF-C687-4B63-998B-B520DF1D1B1B"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:2.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DF18ED7C-80BB-4A78-8809-9AAE817876A4"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:2.2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CA385E01-7FA0-4CC3-ADFE-0B3184A9093D"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:2.2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1D731A35-E0DB-4F40-A981-C38229A2EB1E"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:2.2.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4053C8E5-5510-4814-A46E-89B81266C29D"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:2.2.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8E6753AB-DFCF-4D40-8267-645810F7967E"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:2.2.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4B2B3772-A566-4A51-8B51-68E78C86CB08"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:2.2.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DAFBBAA9-BD46-44E3-9618-D87384E959A2"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:2.2.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "31E594B0-05D5-46C2-8F06-F58E3F8BBD1F"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:2.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "04E0702A-9235-45BE-82A8-BFD57A0DCC9E"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:2.3.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "799F983E-908D-4B9F-9C99-6422863E7807"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:2.3.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BD0914B4-24A9-438F-9B44-A6809D755168"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:2.3.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D29DB4E2-C87F-4D45-BA8A-B38835FCAD44"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EA1A0EF6-1267-463E-B4F7-83D2ACB64E43"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:3.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "90BE006A-0F2D-4F3A-A335-176C5A5978E9"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:3.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "151876D4-B72E-4D5F-A151-5A3DCAE51299"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:3.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "984E8E57-57E5-4FEC-9210-4083AD400F94"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:3.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1760CC7E-5297-4F8A-8A28-3689F6075CAE"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:3.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "74013F50-0677-454E-8E6C-101CF210E989"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:3.0.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "29DC951B-860E-4AF1-8908-71C7099FB19A"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:3.0.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "87198098-906E-4C39-B293-34BBB1779011"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:3.0_beta_2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0A4E9C82-64CF-4487-8947-ED745C41945A"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:3.0_beta_3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D099410F-AD78-4EF1-879E-BEED838B90E0"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:3.0_beta_4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B411D271-87B5-4A82-8E05-5277E8E205E2"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:3.0_beta_5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "09FD2B80-AEB5-444D-AEC3-F59E6727BCF3"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:3.0_beta_6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1CA6003D-1E93-472E-B037-8D0922C4247C"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:3.0_beta_7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5B366723-3598-4B4A-AFB9-E4A9616D033B"
            },
            {
              "criteria": "cpe:2.3:a:jelsoft:vbulletin:3.0_gamma:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0EFD7266-0E3B-44B3-AC8E-DE0BFC5E2939"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}