Description
calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command parameter.
Exploits (1)
References (4)
Core 4
Core References
Various Sources x_refsource_misc
http://www.securiteam.com/exploits/5QP0P158AC.html
Exploit, Patch vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1005284
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/5820
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/10176
Scores
EPSS
0.0826
EPSS Percentile
92.3%
Details
CWE
CWE-78
Status
published
Products (1)
jelsoft/vbulletin
< 2.1.9
Published
Dec 31, 2002
Tracked Since
Feb 18, 2026