CVE-2008-3184
15.07.2008, 18:41
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.6.10 PL2 and earlier, and 3.7.2 and earlier 3.7.x versions, allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO (PHP_SELF) or (2) the do parameter, as demonstrated by requests to upload/admincp/faq.php. NOTE: this issue can be leveraged to execute arbitrary PHP code.
Vendor | Product | Version |
---|---|---|
vbulletin | vbulletin | 3.6 |
vbulletin | vbulletin | 3.6.1 |
vbulletin | vbulletin | 3.6.2 |
vbulletin | vbulletin | 3.6.3 |
vbulletin | vbulletin | 3.6.4 |
vbulletin | vbulletin | 3.6.5 |
vbulletin | vbulletin | 3.6.6 |
vbulletin | vbulletin | 3.6.7 |
vbulletin | vbulletin | 3.6.8 |
vbulletin | vbulletin | 3.6.9 |
vbulletin | vbulletin | 3.6.10 |
vbulletin | vbulletin | 3.6.10:pl1 |
vbulletin | vbulletin | 3.7.0 |
vbulletin | vbulletin | 3.7.1 |
vbulletin | vbulletin | 3.7.1:gold |
vbulletin | vbulletin | 3.7.1:pl1 |
vbulletin | vbulletin | 3.7.2 |
𝑥
= Vulnerable software versions
References