Total vulnerabilities in the database
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.6.10 PL2 and earlier, and 3.7.2 and earlier 3.7.x versions, allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO (PHP_SELF) or (2) the do parameter, as demonstrated by requests to upload/admincp/faq.php. NOTE: this issue can be leveraged to execute arbitrary PHP code.
Software | From | Fixed in |
---|---|---|
vbulletin / vbulletin | 3.6.10-pl1 | 3.6.10-pl1.x |
vbulletin / vbulletin | 3.6.8 | 3.6.8.x |
vbulletin / vbulletin | 3.6.3 | 3.6.3.x |
vbulletin / vbulletin | 3.6.7 | 3.6.7.x |
vbulletin / vbulletin | 3.6.5 | 3.6.5.x |
vbulletin / vbulletin | 3.6.4 | 3.6.4.x |
vbulletin / vbulletin | 3.6 | 3.6.x |
vbulletin / vbulletin | 3.6.2 | 3.6.2.x |
vbulletin / vbulletin | 3.7.1-gold | 3.7.1-gold.x |
vbulletin / vbulletin | 3.7.1 | 3.7.1.x |
vbulletin / vbulletin | 3.6.1 | 3.6.1.x |
vbulletin / vbulletin | 3.7.0 | 3.7.0.x |
vbulletin / vbulletin | 3.7.2 | 3.7.2.x |
vbulletin / vbulletin | 3.6.9 | 3.6.9.x |
vbulletin / vbulletin | 3.6.10 | 3.6.10.x |
vbulletin / vbulletin | 3.6.6 | 3.6.6.x |
vbulletin / vbulletin | 3.7.1-pl1 | 3.7.1-pl1.x |