vBulletin Private Message HTML Injection Vulnerability
BID:7594
Info
vBulletin Private Message HTML Injection Vulnerability
| Bugtraq ID: | 7594 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 14 2003 12:00AM |
| Updated: | May 14 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to "Ferruh Mavituna" <[email protected]>. |
| Vulnerable: |
VBulletin VBulletin 3.0 beta 2 |
| Not Vulnerable: |
VBulletin VBulletin 2.2 .0 |
Discussion
vBulletin Private Message HTML Injection Vulnerability
A vulnerability has been reported in vBulletin 3.0.0 beta 2. The problem is said to occur due to insufficient sanitization of private messages. As a result, an attacker may be capable of embedding malicious HTML or script code within a private message. This code may be interpreted by a legitimate user when previewing the message.
It should be noted that vBulletin 3.0.0 beta 2 is not a public release and has only been made available to a small portion of selected sites. This issue does not affect any public releases of vBulletin.
A vulnerability has been reported in vBulletin 3.0.0 beta 2. The problem is said to occur due to insufficient sanitization of private messages. As a result, an attacker may be capable of embedding malicious HTML or script code within a private message. This code may be interpreted by a legitimate user when previewing the message.
It should be noted that vBulletin 3.0.0 beta 2 is not a public release and has only been made available to a small portion of selected sites. This issue does not affect any public releases of vBulletin.
Exploit / POC
vBulletin Private Message HTML Injection Vulnerability
A proof of concept HTML exploit has been made available:
A proof of concept HTML exploit has been made available:
Solution / Fix
vBulletin Private Message HTML Injection Vulnerability
Solution:
The vulnerable version is not a public release. Any sites that may be running vBulletin 3.0.0 beta 2 should either install a public version or contact the vendor to obtain a fixed version of the beta.
Solution:
The vulnerable version is not a public release. Any sites that may be running vBulletin 3.0.0 beta 2 should either install a public version or contact the vendor to obtain a fixed version of the beta.