CVE-2006-3253
vBulletin 3.0.9/3.5.x - 'member.php' Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in member.php in vBulletin 3.5.x allows remote attackers to inject arbitrary web script or HTML via the u parameter. NOTE: the vendor has disputed this report, stating that they have been unable to replicate the issue and that "the userid parameter is run through our filtering system as an unsigned integer.
** IMPUGNADA ** Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados en member.php en vBulletin v3.5.x permite a atacantes remotos inyectar código web o HTML de su elección a través del parámetro u. NOTA: el vendedor impugna la importancia de este informe, manteniendo que les ha sido imposible reproducir la vulnerabilidad y que "el parámetro userid es filtrado a través de nuestro sistema como un entero sin signo."
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-06-20 First Exploit
- 2006-06-27 CVE Reserved
- 2006-06-27 CVE Published
- 2023-08-23 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://securityreason.com/securityalert/1155 | Third Party Advisory | |
http://www.osvdb.org/27508 | Vdb Entry | |
http://www.securityfocus.com/archive/1/437817/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/438364/100/100/threaded | Mailing List | |
http://www.securityfocus.com/bid/18551 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/27261 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/28076 | 2006-06-20 | |
http://securitytracker.com/id?1016348 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Jelsoft Search vendor "Jelsoft" | Vbulletin Search vendor "Jelsoft" for product "Vbulletin" | 3.5.0 Search vendor "Jelsoft" for product "Vbulletin" and version "3.5.0" | - |
Affected
| ||||||
Jelsoft Search vendor "Jelsoft" | Vbulletin Search vendor "Jelsoft" for product "Vbulletin" | 3.5.0_beta_1 Search vendor "Jelsoft" for product "Vbulletin" and version "3.5.0_beta_1" | - |
Affected
| ||||||
Jelsoft Search vendor "Jelsoft" | Vbulletin Search vendor "Jelsoft" for product "Vbulletin" | 3.5.0_beta_2 Search vendor "Jelsoft" for product "Vbulletin" and version "3.5.0_beta_2" | - |
Affected
| ||||||
Jelsoft Search vendor "Jelsoft" | Vbulletin Search vendor "Jelsoft" for product "Vbulletin" | 3.5.0_beta_3 Search vendor "Jelsoft" for product "Vbulletin" and version "3.5.0_beta_3" | - |
Affected
| ||||||
Jelsoft Search vendor "Jelsoft" | Vbulletin Search vendor "Jelsoft" for product "Vbulletin" | 3.5.0_beta_4 Search vendor "Jelsoft" for product "Vbulletin" and version "3.5.0_beta_4" | - |
Affected
| ||||||
Jelsoft Search vendor "Jelsoft" | Vbulletin Search vendor "Jelsoft" for product "Vbulletin" | 3.5.0_rc1 Search vendor "Jelsoft" for product "Vbulletin" and version "3.5.0_rc1" | - |
Affected
| ||||||
Jelsoft Search vendor "Jelsoft" | Vbulletin Search vendor "Jelsoft" for product "Vbulletin" | 3.5.0_rc2 Search vendor "Jelsoft" for product "Vbulletin" and version "3.5.0_rc2" | - |
Affected
| ||||||
Jelsoft Search vendor "Jelsoft" | Vbulletin Search vendor "Jelsoft" for product "Vbulletin" | 3.5.0_rc3 Search vendor "Jelsoft" for product "Vbulletin" and version "3.5.0_rc3" | - |
Affected
| ||||||
Jelsoft Search vendor "Jelsoft" | Vbulletin Search vendor "Jelsoft" for product "Vbulletin" | 3.5.1 Search vendor "Jelsoft" for product "Vbulletin" and version "3.5.1" | - |
Affected
| ||||||
Jelsoft Search vendor "Jelsoft" | Vbulletin Search vendor "Jelsoft" for product "Vbulletin" | 3.5.2 Search vendor "Jelsoft" for product "Vbulletin" and version "3.5.2" | - |
Affected
| ||||||
Jelsoft Search vendor "Jelsoft" | Vbulletin Search vendor "Jelsoft" for product "Vbulletin" | 3.5.3 Search vendor "Jelsoft" for product "Vbulletin" and version "3.5.3" | - |
Affected
|