Total vulnerabilities in the database
member2.php in vBulletin 2.2.9 and earlier does not properly restrict the $perpage variable to be an integer, which causes an error message to be reflected back to the user without quoting, which facilitates cross-site scripting (XSS) and possibly other attacks.
Software | From | Fixed in |
---|---|---|
jelsoft / vbulletin | 2.2.0 | 2.2.0.x |
jelsoft / vbulletin | 2.2.9_can | 2.2.9_can.x |
jelsoft / vbulletin | 2.2.1 | 2.2.1.x |
jelsoft / vbulletin | 2.0.2 | 2.0.2.x |
jelsoft / vbulletin | 2.0 | 2.0.x |
jelsoft / vbulletin | 2.0.1 | 2.0.1.x |
jelsoft / vbulletin | 2.2.7 | 2.2.7.x |
jelsoft / vbulletin | 2.2.4 | 2.2.4.x |
jelsoft / vbulletin | 2.2.2 | 2.2.2.x |
jelsoft / vbulletin | 2.2.5 | 2.2.5.x |
jelsoft / vbulletin | 2.2.6 | 2.2.6.x |
jelsoft / vbulletin | 2.2.9 | 2.2.9.x |
jelsoft / vbulletin | 2.2.8 | 2.2.8.x |
jelsoft / vbulletin | 2.2.3 | 2.2.3.x |