PT-2005-1491 · Vbulletin Solutions · Vbulletin

Al3Ndaleeb

·

Published

2005-02-15

·

Updated

2016-10-18

·

CVE-2005-0429

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions vBulletin versions 3.0 through 3.0.4
Description A direct code injection issue exists when the showforumusers option is enabled, allowing remote attackers to execute arbitrary PHP commands. This is achieved by injecting code via the comma parameter in the forumdisplay.php file.
Recommendations For vBulletin versions 3.0 through 3.0.4, consider disabling the showforumusers option as a temporary workaround until a patch is available. Restrict access to the forumdisplay.php file to minimize the risk of exploitation. Avoid using the comma parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0429

Affected Products

Vbulletin