PT-2006-6687 · Vbulletin Solutions · Vbulletin

Insanity

·

Published

2006-11-22

·

Updated

2024-08-07

·

CVE-2006-6040

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions vBulletin versions 3.6.x
Description The issue allows remote attackers to inject arbitrary web script or HTML, potentially leading to cross-site scripting (XSS) attacks. This can be achieved via the prefs parameter in a "buildnavprefs" action or the navprefs parameter in a "savenavprefs" action.
Recommendations For vBulletin versions 3.6.x, consider disabling the buildnavprefs and savenavprefs actions until a patch is available to prevent exploitation. Restrict access to the admincp/index.php file to minimize the risk of XSS attacks. Avoid using the prefs and navprefs parameters in the affected actions until the issue is resolved.

Exploit

Fix

Related Identifiers

CVE-2006-6040

Affected Products

Vbulletin