VBulletin Cross-Site Scripting Vulnerability
BID:4349
Info
VBulletin Cross-Site Scripting Vulnerability
| Bugtraq ID: | 4349 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 21 2002 12:00AM |
| Updated: | Mar 21 2002 12:00AM |
| Credit: | Discovery of this issue is credited to <[email protected]>. |
| Vulnerable: |
VBulletin VBulletin 2.2.4 VBulletin VBulletin 2.2.3 VBulletin VBulletin 2.2.2 VBulletin VBulletin 2.2.1 VBulletin VBulletin 2.2 .0 VBulletin VBulletin 2.0 rc 3 VBulletin VBulletin 2.0 rc 2 |
| Not Vulnerable: |
VBulletin VBulletin 2.2.5 |
Discussion
VBulletin Cross-Site Scripting Vulnerability
vBulletin is commercial web forum software written in PHP and back-ended by a MySQL database. It will run on most Linux and Unix variants, as well as Microsoft operating systems.
vBulletin does not filter script code from URL parameters. As a result, it is possible for a remote attacker to create a malicious link containing script code which will be executed in the browser of a legitimate user, in the context of the website running vBulletin.
This issue may be exploited to steal cookie-based authentication credentials from legitimate users of the website running the vulnerable software.
vBulletin is commercial web forum software written in PHP and back-ended by a MySQL database. It will run on most Linux and Unix variants, as well as Microsoft operating systems.
vBulletin does not filter script code from URL parameters. As a result, it is possible for a remote attacker to create a malicious link containing script code which will be executed in the browser of a legitimate user, in the context of the website running vBulletin.
This issue may be exploited to steal cookie-based authentication credentials from legitimate users of the website running the vulnerable software.
Exploit / POC
VBulletin Cross-Site Scripting Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
VBulletin Cross-Site Scripting Vulnerability
Solution:
The vendor has acknowledged this issue and a fix is expected shortly.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The vendor has acknowledged this issue and a fix is expected shortly.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.