Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.100020
Category:Web application abuses
Title:vBulletin 'admincalendar.php' SQL Injection Vulnerability
Summary:vBulletin is prone to an SQL-injection vulnerability because it; fails to sufficiently sanitize user-supplied data before using it in; an SQL query.
Description:Summary:
vBulletin is prone to an SQL-injection vulnerability because it
fails to sufficiently sanitize user-supplied data before using it in
an SQL query.

Vulnerability Impact:
Exploiting this issue could allow an attacker to compromise the
application, access or modify data, or exploit latent vulnerabilities in the underlying database.

Note that to succeed, the attacker must have an administrative
account with 'calendar' administrator access.

Affected Software/OS:
vBulletin 3.7.3.pl1 is vulnerable, other versions may also be affected.

Solution:
Upgrade to the newest version of vBulletin.

CVSS Score:
6.5

CVSS Vector:
AV:N/AC:L/Au:S/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2008-6256
Bugtraq: 20081117 [waraxe-2008-SA#068] - Sql Injection in vBulletin 3.7.3.pl1 (Google Search)
http://www.securityfocus.com/archive/1/498369/100/0/threaded
http://www.waraxe.us/advisory-68.html
http://secunia.com/advisories/32735
XForce ISS Database: vbulletin-admincalendar-sql-injection(46683)
https://exchange.xforce.ibmcloud.com/vulnerabilities/46683
CopyrightCopyright (C) 2009 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.