PT-2006-3047 · Vbulletin+1 · Vbulletin+1

Mustafa Can Bjorn Ipekci

+1

·

Published

2006-04-27

·

Updated

2018-10-18

·

CVE-2006-2066

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions MKPortal versions 1.1 Rc1 and earlier vBulletin versions 3.5.4 and earlier
Description The issue allows remote attackers to inject arbitrary web script or HTML via the u1, m1, m2, m3, m4 parameters in the pm popup.php file.
Recommendations For MKPortal versions 1.1 Rc1 and earlier, avoid using the parameters u1, m1, m2, m3, m4 in the pm popup.php file until a fix is available. For vBulletin versions 3.5.4 and earlier, restrict access to the pm popup.php file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-2066

Affected Products

Mkportal
Vbulletin