20021123 vBulletin XSS Injection Vulnerabilitymailing list
http://online.securityfocus.com/archive/1/301076 CVE-2002-2235
vBulletin 2.0.x/2.2.x - 'members2.php' Cross-Site Scripting
Record summary
CVE-2002-2235 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
member2.php in vBulletin 2.2.9 and earlier does not properly restrict the $perpage variable to be an integer, which causes an error message to be reflected back to the user without quoting, which facilitates cross-site scripting (XSS) and possibly other attacks.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBvBulletin 2.0.x/2.2.x - 'members2.php' Cross-Site ScriptingExploitDB exploitby Sp.ICNot analyzed1 file
References
53229Third-party advisory
http://securityreason.com/securityalert/3229 vbulletin-member2-perpage-xss(10701)vdb entry
http://www.iss.net/security_center/static/10701.php 6246vdb entry
http://www.securityfocus.com/bid/6246 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-2235