Lucene search

K
cveMitreCVE-2005-3025
HistorySep 21, 2005 - 10:03 p.m.

CVE-2005-3025

2005-09-2122:03:00
mitre
web.nvd.nist.gov
25
vbulletin
xss
cross-site scripting
security
vulnerability
web script
html
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.002

Percentile

56.8%

Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the loc parameter to (1) modcp/index.php or (2) admincp/index.php, or the ip parameter to (3) modcp/user.php or (4) admincp/usertitle.php.

Affected configurations

Nvd
Node
jelsoftvbulletinMatch1.0.1lite
OR
jelsoftvbulletinMatch2.0.3
OR
jelsoftvbulletinMatch2.0_rc2
OR
jelsoftvbulletinMatch2.0_rc3
OR
jelsoftvbulletinMatch2.2.0
OR
jelsoftvbulletinMatch2.2.1
OR
jelsoftvbulletinMatch2.2.2
OR
jelsoftvbulletinMatch2.2.3
OR
jelsoftvbulletinMatch2.2.4
OR
jelsoftvbulletinMatch2.2.5
OR
jelsoftvbulletinMatch2.2.6
OR
jelsoftvbulletinMatch2.2.7
OR
jelsoftvbulletinMatch2.2.8
OR
jelsoftvbulletinMatch2.2.9
OR
jelsoftvbulletinMatch2.3.0
OR
jelsoftvbulletinMatch2.3.2
OR
jelsoftvbulletinMatch2.3.3
OR
jelsoftvbulletinMatch2.3.4
OR
jelsoftvbulletinMatch3.0
OR
jelsoftvbulletinMatch3.0.1
OR
jelsoftvbulletinMatch3.0.2
OR
jelsoftvbulletinMatch3.0.3
OR
jelsoftvbulletinMatch3.0.4
OR
jelsoftvbulletinMatch3.0.5
OR
jelsoftvbulletinMatch3.0.6
OR
jelsoftvbulletinMatch3.0.7
OR
jelsoftvbulletinMatch3.0_beta_2
OR
jelsoftvbulletinMatch3.0_beta_3
OR
jelsoftvbulletinMatch3.0_beta_4
OR
jelsoftvbulletinMatch3.0_beta_5
OR
jelsoftvbulletinMatch3.0_beta_6
OR
jelsoftvbulletinMatch3.0_beta_7
OR
jelsoftvbulletinMatch3.0_gamma
VendorProductVersionCPE
jelsoftvbulletin1.0.1cpe:2.3:a:jelsoft:vbulletin:1.0.1:*:lite:*:*:*:*:*
jelsoftvbulletin2.0.3cpe:2.3:a:jelsoft:vbulletin:2.0.3:*:*:*:*:*:*:*
jelsoftvbulletin2.0_rc2cpe:2.3:a:jelsoft:vbulletin:2.0_rc2:*:*:*:*:*:*:*
jelsoftvbulletin2.0_rc3cpe:2.3:a:jelsoft:vbulletin:2.0_rc3:*:*:*:*:*:*:*
jelsoftvbulletin2.2.0cpe:2.3:a:jelsoft:vbulletin:2.2.0:*:*:*:*:*:*:*
jelsoftvbulletin2.2.1cpe:2.3:a:jelsoft:vbulletin:2.2.1:*:*:*:*:*:*:*
jelsoftvbulletin2.2.2cpe:2.3:a:jelsoft:vbulletin:2.2.2:*:*:*:*:*:*:*
jelsoftvbulletin2.2.3cpe:2.3:a:jelsoft:vbulletin:2.2.3:*:*:*:*:*:*:*
jelsoftvbulletin2.2.4cpe:2.3:a:jelsoft:vbulletin:2.2.4:*:*:*:*:*:*:*
jelsoftvbulletin2.2.5cpe:2.3:a:jelsoft:vbulletin:2.2.5:*:*:*:*:*:*:*
Rows per page:
1-10 of 331

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.002

Percentile

56.8%

Related for CVE-2005-3025