PT-2014-8676 · Vbulletin Solutions · Vbulletin

Published

2014-11-06

·

Updated

2017-09-08

·

CVE-2014-8670

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions vBulletin version 4.2.1
Description The issue allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter. This can be exploited by providing a malicious URL to the vulnerable go.php endpoint.
Recommendations For version 4.2.1, update to a newer version that contains a fix for this issue to prevent remote attackers from redirecting users to arbitrary web sites.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2014-8670

Affected Products

Vbulletin