PT-2004-3585 · Vbulletin Solutions · Vbulletin

Published

2004-12-31

·

Updated

2020-02-24

·

CVE-2004-2695

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions vBulletin versions 3.0 through 3.0.3
Description The issue is related to a SQL injection vulnerability in the Authorize.net callback code, specifically in the subscriptions/authorize.php file. This vulnerability allows remote attackers to execute arbitrary SQL statements via the x invoice num parameter.
Recommendations For versions 3.0 through 3.0.3, consider restricting access to the vulnerable subscriptions/authorize.php file until a patch is available. Avoid using the x invoice num parameter in the affected code to minimize the risk of exploitation.

Fix

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2004-2695

Affected Products

Vbulletin