PT-2006-3047 · Vbulletin+1 · Vbulletin+1
Mustafa Can Bjorn Ipekci
+1
·
Published
2006-04-27
·
Updated
2018-10-18
·
CVE-2006-2066
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
MKPortal versions 1.1 Rc1 and earlier
vBulletin versions 3.5.4 and earlier
Description
The issue allows remote attackers to inject arbitrary web script or HTML via the
u1, m1, m2, m3, m4 parameters in the pm popup.php file.Recommendations
For MKPortal versions 1.1 Rc1 and earlier, avoid using the parameters
u1, m1, m2, m3, m4 in the pm popup.php file until a fix is available.
For vBulletin versions 3.5.4 and earlier, restrict access to the pm popup.php file to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mkportal
Vbulletin