PT-2004-1295 · Vbulletin · Vbulletin
Ferruh Mavituna
·
Published
2004-01-22
·
Updated
2024-08-08
·
CVE-2004-0091
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
vBulletin (affected versions not specified)
Description
A cross-site scripting (XSS) issue in register.php allows remote attackers to inject arbitrary HTML or web script via the
reg site (or possibly regsite) parameter. The vendor has disputed this issue, stating that there is no hidden field called 'reg site' nor any $reg site variable in the vBulletin 2 or vBulletin 3 source code or templates.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vbulletin