PT-2004-3585 · Vbulletin Solutions · Vbulletin
Published
2004-12-31
·
Updated
2020-02-24
·
CVE-2004-2695
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
vBulletin versions 3.0 through 3.0.3
Description
The issue is related to a SQL injection vulnerability in the Authorize.net callback code, specifically in the subscriptions/authorize.php file. This vulnerability allows remote attackers to execute arbitrary SQL statements via the
x invoice num parameter.Recommendations
For versions 3.0 through 3.0.3, consider restricting access to the vulnerable
subscriptions/authorize.php file until a patch is available. Avoid using the x invoice num parameter in the affected code to minimize the risk of exploitation.Fix
RCE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vbulletin