Vulnerability index

Browse CVEs

31 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Vbulletin HIGH 9.3
CVE-2007-4120

Multiple PHP remote file inclusion vulnerabilities in Jelsoft vBulletin 3.6.5 allow remote attackers to execute arbitrary PHP code via a URL in the (…

No fix yet
Fix from $1,950 2007-08-01
Vbulletin MEDIUM 5.8
CVE-2007-3326

Multiple directory traversal vulnerabilities in vBulletin 3.x.x allow remote attackers to redirect visitors to arbitrary local files via a .. (dot do…

Mitigation only
Fix from $1,600 2007-06-21
Vbsupport Integrated Ticket System HIGH 7.5
CVE-2007-3196

SQL injection vulnerability in vBSupport.php in vSupport Integrated Ticket System 3.x.x allows remote attackers to execute arbitrary SQL commands via…

No fix yet
Fix from $1,950 2007-06-12
Vbsupport Integrated Ticket System HIGH 7.5
CVE-2007-3197

SQL injection vulnerability in vBSupport.php in vBSupport 1.1 before 1.1a allows remote attackers to execute arbitrary SQL commands via unspecified v…

Fix: after 1.1
Fix from $1,950 2007-06-12
Vbulletin HIGH 8.5
CVE-2007-2911

SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin before 3.6.6 allows remote authenticated administrators to execute arbitra…

Fix: after 3.6.5
Fix from $1,950 2007-05-30
Vbulletin MEDIUM 5.0
CVE-2007-2912

Unspecified vulnerability in Jelsoft vBulletin before 3.6.6, when unauthenticated User Infraction Permissions is disabled, allows remote attackers to…

Fix: after 3.6.4
Fix from $1,600 2007-05-30
Vbulletin MEDIUM 6.0
CVE-2007-1573

SQL injection vulnerability in admincp/attachment.php in Jelsoft vBulletin 3.6.5 allows remote authenticated administrators to execute arbitrary SQL …

Fix: after 3.6.5
Fix from $1,600 2007-03-21
Vbulletin HIGH 7.5
CVE-2007-1292

SQL injection vulnerability in inlinemod.php in Jelsoft vBulletin before 3.5.8, and before 3.6.5 in the 3.6.x series, might allow remote authenticate…

Fix: after 3.5.8
Fix from $1,950 2007-03-07
Vbulletin MEDIUM 6.8
CVE-2006-6779

Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin allows remote attackers to inject arbitrary web script or HTML via an SWF file that use…

No fix yet
Fix from $1,600 2006-12-28
Vbulletin MEDIUM 6.8
CVE-2006-6040

Multiple cross-site scripting (XSS) vulnerabilities in admincp/index.php in Jelsoft vBulletin 3.6.x allow remote attackers to inject arbitrary web sc…

Patch available
Fix from $1,600 2006-11-22
Vbulletin HIGH 7.5
CVE-2006-5104

SQL injection vulnerability in global.php in Jelsoft vBulletin 2.x allows remote attackers to execute arbitrary SQL commands via the templatesused pa…

No fix yet
Fix from $1,950 2006-10-03
Vbulletin HIGH 7.5
CVE-2006-4271

PHP remote file inclusion vulnerability in install/upgrade_301.php in Jelsoft vBulletin 3.5.4 allows remote attackers to execute arbitrary PHP code v…

No fix yet
Fix from $1,950 2006-08-21
Vbulletin HIGH 7.5
CVE-2006-4272

Jelsoft vBulletin 3.5.4 allows remote attackers to register multiple arbitrary users and cause a denial of service (resource consumption) via a large…

Mitigation only
Fix from $1,950 2006-08-21
Vbulletin MEDIUM 6.8
CVE-2006-4273

Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 3.5.4 and 3.6.0 allows remote attackers to inject arbitrary web script or HTML by uploa…

No fix yet
Fix from $1,600 2006-08-21
Vbulletin MEDIUM 5.0
CVE-2006-2805

SQL injection vulnerability in VBulletin 3.0.10 allows remote attackers to execute arbitrary SQL commands via the featureid parameter.

No fix yet
Fix from $1,600 2006-06-03
Vbulletin MEDIUM 6.5
CVE-2006-2335

Jelsoft vBulletin accepts uploads of Cascading Style Sheets (CSS) and processes them in a way that allows remote authenticated administrators to gain…

No fix yet
Fix from $1,600 2006-05-12
Vbulletin HIGH 7.5
CVE-2006-2018

SQL injection vulnerability in calendar.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL commands via the eventid parameter. …

No fix yet
Fix from $1,950 2006-04-25
Vbulletin MEDIUM 5.0
CVE-2006-1816

PHP remote file inclusion vulnerability in VBulletin 3.5.1, 3.5.2, and 3.5.4 allows remote attackers to execute arbitrary code via a URL in the syste…

Mitigation only
Fix from $1,600 2006-04-18
Impex HIGH 7.5
CVE-2006-1382

PHP remote file inclusion vulnerability in impex/ImpExData.php in vBulletin ImpEx module 1.74, when register_globals is disabled, allows remote attac…

Fix: after 1.74
Fix from $1,950 2006-03-24
Vbulletin HIGH 7.5
CVE-2005-3019

Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL commands via the (1) request paramet…

Patch available
Fix from $1,950 2005-09-21
Vbulletin HIGH 7.5
CVE-2005-3022

Multiple SQL injection vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) announceme…

No fix yet
Fix from $1,950 2005-09-21
Vbulletin HIGH 7.5
CVE-2005-3024

Multiple SQL injection vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) announceme…

Patch available
Fix from $1,950 2005-09-21
Vbulletin MEDIUM 5.0
CVE-2005-0429

Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showforumusers is enabled, allows remote attackers to ex…

Mitigation only
Fix from $1,600 2005-05-02
Vbulletin HIGH 7.5
CVE-2005-0511EPSS 36%

misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code…

Patch available
Fix from $1,950 2005-02-21
Vbulletin HIGH 7.5
CVE-2004-1515

SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL statements via t…

Mitigation only
Fix from $1,950 2004-12-31
Vbulletin HIGH 7.5
CVE-2004-2695

SQL injection vulnerability in the Authorize.net callback code (subscriptions/authorize.php) in Jelsoft vBulletin 3.0 through 3.0.3 allows remote att…

Patch available
Fix from $1,950 2004-12-31
Vbulletin MEDIUM 5.0
CVE-2004-0036

SQL injection vulnerability in calendar.php for vBulletin Forum 2.3.x before 2.3.4 allows remote attackers to steal sensitive information via the eve…

Mitigation only
Fix from $1,600 2004-01-20
Vbulletin MEDIUM 6.8
CVE-2003-0295

Cross-site scripting (XSS) vulnerability in private.php for vBulletin 3.0.0 Beta 2 allows remote attackers to inject arbitrary web script and HTML vi…

Mitigation only
Fix from $1,600 2003-06-16
Vbulletin HIGH 7.5
CVE-2002-1660EPSS 11%

calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command parameter.

Fix: after 2.1.9
Fix from $1,950 2002-12-31
Vbulletin MEDIUM 5.0
CVE-2002-2235

member2.php in vBulletin 2.2.9 and earlier does not properly restrict the $perpage variable to be an integer, which causes an error message to be ref…

No fix yet
Fix from $1,600 2002-12-31