CVE-2014-5102
25.07.2014, 19:55
SQL injection vulnerability in vBulletin 5.0.4 through 5.1.3 Alpha 5 allows remote attackers to execute arbitrary SQL commands via the criteria[startswith] parameter to ajax/render/memberlist_items.
Vendor | Product | Version |
---|---|---|
vbulletin | vbulletin | 5.0.4 |
vbulletin | vbulletin | 5.0.5 |
vbulletin | vbulletin | 5.1.0 |
vbulletin | vbulletin | 5.1.0:rc1 |
vbulletin | vbulletin | 5.1.1 |
vbulletin | vbulletin | 5.1.2 |
vbulletin | vbulletin | 5.1.2:beta1 |
vbulletin | vbulletin | 5.1.2:rc1 |
vbulletin | vbulletin | 5.1.2:rc2 |
vbulletin | vbulletin | 5.1.3:alpha5 |
𝑥
= Vulnerable software versions
References