Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2005-3020

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2005-3020
Last Modified 05 Sep 2008 04:53:14
Published 21 Sep 2005 06:03:00
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2005-3020

Summary

Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to css.php, (2) redirect parameter to index.php, (3) email parameter to user.php, (4) goto parameter to language.php, (5) orderby parameter to modlog.php, and the (6) hex, (7) rgb, or (8) expandset parameter to template.php.

Vulnerable Systems

Application

  • Jelsoft Vbulletin 1.0.1

  • Jelsoft Vbulletin 2.0 Rc2

  • Jelsoft Vbulletin 2.0 Rc3

  • Jelsoft Vbulletin 2.0.3

  • Jelsoft Vbulletin 2.2.0

  • Jelsoft Vbulletin 2.2.1

  • Jelsoft Vbulletin 2.2.2

  • Jelsoft Vbulletin 2.2.3

  • Jelsoft Vbulletin 2.2.4

  • Jelsoft Vbulletin 2.2.5

  • Jelsoft Vbulletin 2.2.6

  • Jelsoft Vbulletin 2.2.7

  • Jelsoft Vbulletin 2.2.8

  • Jelsoft Vbulletin 2.2.9

  • Jelsoft Vbulletin 2.3.0

  • Jelsoft Vbulletin 2.3.2

  • Jelsoft Vbulletin 2.3.3

  • Jelsoft Vbulletin 2.3.4

  • Jelsoft Vbulletin 3.0

  • Jelsoft Vbulletin 3.0 Beta 2

  • Jelsoft Vbulletin 3.0 Beta 3

  • Jelsoft Vbulletin 3.0 Beta 4

  • Jelsoft Vbulletin 3.0 Beta 5

  • Jelsoft Vbulletin 3.0 Beta 6

  • Jelsoft Vbulletin 3.0 Beta 7

  • Jelsoft Vbulletin 3.0 Gamma

  • Jelsoft Vbulletin 3.0.1

  • Jelsoft Vbulletin 3.0.2

  • Jelsoft Vbulletin 3.0.3

  • Jelsoft Vbulletin 3.0.4

  • Jelsoft Vbulletin 3.0.5

  • Jelsoft Vbulletin 3.0.6

  • Jelsoft Vbulletin 3.0.7

  • Jelsoft Vbulletin 3.0.8

  • Jelsoft Vbulletin 3.0.9


References

XF - vbulletin-xss(22324)

BID - 14874

SECUNIA - 16873

MISC - http://morph3us.org/advisories/20050917-vbulletin-3.0.8.txt

BUGTRAQ - 20050918 [BuHa-Security] Multiple vulnerabilities in (admincp/modcp of)


Last Updated: 27 May 2016 10:40:43