
CVE-2006-1382
https://notcve.org/view.php?id=CVE-2006-1382
24 Mar 2006 — PHP remote file inclusion vulnerability in impex/ImpExData.php in vBulletin ImpEx module 1.74, when register_globals is disabled, allows remote attackers to include arbitrary files via the systempath parameter. • http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/044318.html •

CVE-2006-1040 – vBulletin 3.0/3.5 - 'profile.php?Email' HTML Injection
https://notcve.org/view.php?id=CVE-2006-1040
07 Mar 2006 — Cross-site scripting (XSS) vulnerability in vBulletin 3.0.12 and 3.5.3 allows remote attackers to inject arbitrary web script or HTML via the email field, which is injected in profile.php but not sanitized in sendmsg.php. • https://www.exploit-db.com/exploits/27343 •

CVE-2006-0080
https://notcve.org/view.php?id=CVE-2006-0080
04 Jan 2006 — Cross-site scripting (XSS) vulnerability in vBulletin 3.5.2, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the title of an event, which is not properly filtered by (1) calendar.php and (2) reminder.php. • http://kapda.ir/advisory-177.html •

CVE-2005-4621
https://notcve.org/view.php?id=CVE-2005-4621
31 Dec 2005 — Cross-site scripting (XSS) vulnerability in the editavatar page in vBulletin 3.5.1 allows remote attackers to inject arbitrary web script or HTML via a URL in the remote avatar url field, in which the URL generates a parsing error, and possibly requiring a trailing extension such as .jpg. • http://pridels0.blogspot.com/2005/11/vbulletin-351-xss-vuln.html •

CVE-2005-3025
https://notcve.org/view.php?id=CVE-2005-3025
21 Sep 2005 — Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the loc parameter to (1) modcp/index.php or (2) admincp/index.php, or the ip parameter to (3) modcp/user.php or (4) admincp/usertitle.php. • http://marc.info/?l=bugtraq&m=112732980702939&w=2 •

CVE-2005-3021
https://notcve.org/view.php?id=CVE-2005-3021
21 Sep 2005 — image.php in vBulletin 3.0.9 and earlier allows remote attackers with access to the administrator panel to upload arbitrary files via the upload action. • http://marc.info/?l=bugtraq&m=112715150320677&w=2 •

CVE-2005-3024
https://notcve.org/view.php?id=CVE-2005-3024
21 Sep 2005 — Multiple SQL injection vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) announcement parameter to announcement.php, the (2) thread[forumid] or (3) criteria parameters to thread.php, (4) userid parameter to user.php, the (5) calendarcustomfieldid, (6) calendarid, (7) moderatorid, (8) holidayid, (9) calendarmoderatorid, or (10) calendar[0] parameters to admincalendar.php, (11) the cronid parameter to cronlog.php, (12) user[usergroupid][0] para... • http://marc.info/?l=bugtraq&m=112732980702939&w=2 •

CVE-2005-3022
https://notcve.org/view.php?id=CVE-2005-3022
21 Sep 2005 — Multiple SQL injection vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) announcement parameter to announcement.php, (2) userid parameter to user.php, (3) calendar parameter to admincalendar.php, (4) cronid parameter to cronlog.php, (5) usergroupid parameter to email.php, (6) help parameter to help.php, (7) rvt parameter to language.php, (8) keep parameter to phrase.php, or (9) updateprofilepic parameter to usertools.php. • http://marc.info/?l=bugtraq&m=112715150320677&w=2 •

CVE-2005-3023
https://notcve.org/view.php?id=CVE-2005-3023
21 Sep 2005 — Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) announcement.php, (2) admincalendar.php, (3) bbcode.php, (4) cronadmin.php, (5) email.php, (6) faq.php, (7) forum.php, (8) image.php, (9) language.php, (10) ranks.php, (11) replacement.php, (12) replacement.php, (13) template.php, (14) template.php, (15) usergroup.php, or (16) usertitle.php. • http://marc.info/?l=bugtraq&m=112715150320677&w=2 •

CVE-2005-3019 – vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/user.php' Multiple SQL Injections
https://notcve.org/view.php?id=CVE-2005-3019
21 Sep 2005 — Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL commands via the (1) request parameter to joinrequests.php, (2) limitnumber or (3) limitstart to user.php, (4) usertitle.php, or (5) usertools.php. • https://www.exploit-db.com/exploits/26274 •