CVE-2004-0620
vBulletin 3.0.1 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in (1) newreply.php or (2) newthread.php in vBulletin 3.0.1 allows remote attackers to inject arbitrary HTML or script as other users via the Edit-panel.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Cheng Peng Su · htmlwebappsphp
https://www.exploit-db.com/exploits/24234
Scores
EPSS
0.0379
EPSS Percentile
88.1%
Details
Status
published
Products (1)
jelsoft/vbulletin
3.0.1
Published
Dec 06, 2004
Tracked Since
Feb 18, 2026