Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showforumusers is enabled, allows remote attackers to execute inject arbitrary PHP commands via the comma parameter.
| Software | From | Fixed in |
|---|---|---|
| jelsoft / vbulletin | 3.0.4 | 3.0.4.x |
| jelsoft / vbulletin | 3.0.1 | 3.0.1.x |
| jelsoft / vbulletin | 3.0.2 | 3.0.2.x |
| jelsoft / vbulletin | 3.0.3 | 3.0.3.x |
| jelsoft / vbulletin | 3.0 | 3.0.x |