20040624 vBulletin HTML Injection Vulnmailing list
http://marc.info/?l=bugtraq&m=108809720026642&w=2 CVE-2004-0620
vBulletin 3.0.1 - 'newreply.php?WYSIWYG_HTML' Cross-Site Scripting
Record summary
CVE-2004-0620 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
Cross-site scripting (XSS) vulnerability in (1) newreply.php or (2) newthread.php in vBulletin 3.0.1 allows remote attackers to inject arbitrary HTML or script as other users via the Edit-panel.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBvBulletin 3.0.1 - 'newreply.php?WYSIWYG_HTML' Cross-Site ScriptingExploitDB exploitby Cheng Peng SuNot analyzed1 file
References
410602vdb entry
http://www.securityfocus.com/bid/10602 vbulletin-newreply-newthread-xss(16502)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/16502 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-0620