VBulletin Image Tag Cross-Agent Scripting Vulnerability
BID:4315
Info
VBulletin Image Tag Cross-Agent Scripting Vulnerability
| Bugtraq ID: | 4315 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 19 2002 12:00AM |
| Updated: | Mar 19 2002 12:00AM |
| Credit: | DIscovery of this issue is credited to Cano2 <[email protected]>. |
| Vulnerable: |
VBulletin VBulletin 2.2.2 VBulletin VBulletin 2.2.1 VBulletin VBulletin 2.2 .0 VBulletin VBulletin 2.0 rc 3 VBulletin VBulletin 2.0 rc 2 |
| Not Vulnerable: |
VBulletin VBulletin 2.2.4 VBulletin VBulletin 2.2.3 |
Discussion
VBulletin Image Tag Cross-Agent Scripting Vulnerability
vBulletin is commercial web forum software written in PHP and back-ended by a MySQL database. It will run on most Linux and Unix variants, as well as Microsoft operating systems.
vBulletin includes functionality to allow forum users to post images in messages. To post an image, a user simply includes a link to the image inside of [img] tags. However, vBulletin does not adequately filter script code from image tags, making it prone to cross-agent scripting attacks.
Additionally, it has been reported that script code is not filtered from other tags, such as [url], [email], etc.
It is not known whether vBulletin Lite is also affected by this vulnerability.
vBulletin is commercial web forum software written in PHP and back-ended by a MySQL database. It will run on most Linux and Unix variants, as well as Microsoft operating systems.
vBulletin includes functionality to allow forum users to post images in messages. To post an image, a user simply includes a link to the image inside of [img] tags. However, vBulletin does not adequately filter script code from image tags, making it prone to cross-agent scripting attacks.
Additionally, it has been reported that script code is not filtered from other tags, such as [url], [email], etc.
It is not known whether vBulletin Lite is also affected by this vulnerability.
Exploit / POC
VBulletin Image Tag Cross-Agent Scripting Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.