Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.811314
Category:Web application abuses
Title:vBulletin Forum 'forum/help' Page Cross Site Scripting Vulnerability
Summary:vBulletin is prone to a cross-site scripting (XSS) vulnerability.
Description:Summary:
vBulletin is prone to a cross-site scripting (XSS) vulnerability.

Vulnerability Insight:
The flaw exists due to the programming code
flaw occurs at 'forum/help' page. Add 'hash symbol' first. Then add script at
the end of it.

Vulnerability Impact:
Successfully exploiting this issue allow
remote attackers to execute arbitrary script code in the browser of an
unsuspecting user in the context of the affected site. This may allow the
attacker to steal cookie-based authentication credentials and launch other
attacks.

Affected Software/OS:
vBulletin versions 5.1.3, 5.0.5, 4.2.2, 3.8.7,
3.6.7, 3.6.0 and 3.5.4.

Solution:
Update to the latest available version.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Cross-Ref: BugTraq ID: 72592
Common Vulnerability Exposure (CVE) ID: CVE-2014-9469
http://www.securityfocus.com/bid/72592
http://seclists.org/fulldisclosure/2015/Feb/49
http://packetstormsecurity.com/files/130393/vBulletin-5.1.3-Cross-Site-Scripting.html
CopyrightCopyright (C) 2017 Greenbone Networks GmbH

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2024 E-Soft Inc. All rights reserved.