PT-2006-5083 · Vbulletin+1 · Vbulletin+1
Published
2006-08-21
·
Updated
2018-10-17
·
CVE-2006-4273
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
vBulletin versions 3.5.4 through 3.6.0
Description
A cross-site scripting issue allows remote attackers to inject arbitrary web script or HTML by uploading an attachment with a .pdf extension that contains JavaScript. This JavaScript is processed as script by Microsoft Internet Explorer 6.
Recommendations
For versions 3.5.4 and 3.6.0, consider disabling the attachment upload feature until a fix is available, or restrict the types of files that can be uploaded to prevent malicious attachments.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Explorer 6
Vbulletin