VBulletin Registration Requests Remote Denial of Service Vulnerability
BID:20581
Info
VBulletin Registration Requests Remote Denial of Service Vulnerability
| Bugtraq ID: | 20581 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 17 2006 12:00AM |
| Updated: | Oct 18 2006 06:19PM |
| Credit: | m4k3 has been creditied with the discovery of this vulnerability. |
| Vulnerable: |
VBulletin VBulletin 3.5.4 VBulletin VBulletin 3.5.3 VBulletin VBulletin 3.5.2 VBulletin VBulletin 3.5.1 VBulletin VBulletin 3.0.15 VBulletin VBulletin 3.0.14 VBulletin VBulletin 3.0.12 VBulletin VBulletin 3.0.11 VBulletin VBulletin 3.0.10 VBulletin VBulletin 3.0.9 VBulletin VBulletin 3.0.8 VBulletin VBulletin 3.0.7 VBulletin VBulletin 3.0.6 VBulletin VBulletin 3.0.5 VBulletin VBulletin 3.0.4 VBulletin VBulletin 3.0.3 VBulletin VBulletin 3.0.2 VBulletin VBulletin 3.0.1 VBulletin VBulletin 3.0 Gamma VBulletin VBulletin 3.0 beta 7 VBulletin VBulletin 3.0 beta 6 VBulletin VBulletin 3.0 beta 5 VBulletin VBulletin 3.0 beta 4 VBulletin VBulletin 3.0 beta 3 VBulletin VBulletin 3.0 beta 2 VBulletin VBulletin 3.0 VBulletin VBulletin 2.3.8 VBulletin VBulletin 2.3.4 VBulletin VBulletin 2.3.3 VBulletin VBulletin 2.3.2 VBulletin VBulletin 2.3 .0 VBulletin VBulletin 2.2.9 VBulletin VBulletin 2.2.8 VBulletin VBulletin 2.2.7 VBulletin VBulletin 2.2.6 VBulletin VBulletin 2.2.5 VBulletin VBulletin 2.2.4 VBulletin VBulletin 2.2.3 VBulletin VBulletin 2.2.2 VBulletin VBulletin 2.2.1 VBulletin VBulletin 2.2 .0 VBulletin VBulletin 2.0.3 VBulletin VBulletin 2.0 rc 3 VBulletin VBulletin 2.0 rc 2 |
| Not Vulnerable: | |
Discussion
VBulletin Registration Requests Remote Denial of Service Vulnerability
VBulletin is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users.
VBulletin 3.6.0 and prior versions are vulnerable to this issue.
VBulletin is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users.
VBulletin 3.6.0 and prior versions are vulnerable to this issue.
Exploit / POC
VBulletin Registration Requests Remote Denial of Service Vulnerability
An attacker can exploit this issue via a web client.
The following exploit code is available:
An attacker can exploit this issue via a web client.
The following exploit code is available:
Solution / Fix
VBulletin Registration Requests Remote Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
VBulletin Registration Requests Remote Denial of Service Vulnerability
References:
References: