Lucene search

K
cveMitreCVE-2001-0475
HistorySep 18, 2001 - 4:00 a.m.

CVE-2001-0475

2001-09-1804:00:00
mitre
web.nvd.nist.gov
33
cve-2001-0475
jelsoft
vbulletin
php
remote code execution
information security
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

Low

EPSS

0.009

Percentile

82.7%

index.php in Jelsoft vBulletin does not properly initialize a PHP variable that is used to store template information, which allows remote attackers to execute arbitrary PHP code via special characters in the templatecache parameter.

Affected configurations

Nvd
Node
jelsoftvbulletinRange1.1.5
OR
jelsoftvbulletinRange2.0_beta_2
VendorProductVersionCPE
jelsoftvbulletin*cpe:2.3:a:jelsoft:vbulletin:*:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

Low

EPSS

0.009

Percentile

82.7%

Related for CVE-2001-0475