Lucene search

K
cve[email protected]CVE-2005-0511
HistoryFeb 23, 2005 - 5:00 a.m.

CVE-2005-0511

2005-02-2305:00:00
web.nvd.nist.gov
23
cve-2005-0511
vbulletin
remote code execution
nvd
security vulnerability

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.5 High

AI Score

Confidence

High

0.891 High

EPSS

Percentile

98.8%

misc.php for vBulletin 3.0.6 and earlier, when “Add Template Name in HTML Comments” is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.

Affected configurations

NVD
Node
jelsoftvbulletinMatch2.0
OR
jelsoftvbulletinMatch2.0.1
OR
jelsoftvbulletinMatch2.0.2
OR
jelsoftvbulletinMatch2.0_beta_2
OR
jelsoftvbulletinMatch2.0_beta_3
OR
jelsoftvbulletinMatch2.2.0
OR
jelsoftvbulletinMatch2.2.1
OR
jelsoftvbulletinMatch2.2.2
OR
jelsoftvbulletinMatch2.2.3
OR
jelsoftvbulletinMatch2.2.4
OR
jelsoftvbulletinMatch2.2.5
OR
jelsoftvbulletinMatch2.2.6
OR
jelsoftvbulletinMatch2.2.7
OR
jelsoftvbulletinMatch2.2.8
OR
jelsoftvbulletinMatch2.2.9_can
OR
jelsoftvbulletinMatch2.3.0
OR
jelsoftvbulletinMatch2.3.3
OR
jelsoftvbulletinMatch2.3.4
OR
jelsoftvbulletinMatch3.0.0
OR
jelsoftvbulletinMatch3.0.0_beta_2
OR
jelsoftvbulletinMatch3.0.0_can4
OR
jelsoftvbulletinMatch3.0.0_rc4
OR
jelsoftvbulletinMatch3.0.1
OR
jelsoftvbulletinMatch3.0.2
OR
jelsoftvbulletinMatch3.0.3
OR
jelsoftvbulletinMatch3.0.4
OR
jelsoftvbulletinMatch3.0.5
OR
jelsoftvbulletinMatch3.0.6
OR
jelsoftvbulletinMatch3.0_beta_2

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.5 High

AI Score

Confidence

High

0.891 High

EPSS

Percentile

98.8%

Related for CVE-2005-0511