CVE-2004-1515

vBulletin 3.0.x - SQL Injection via fsel Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-1515. PoCs published by anonymous.

AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in the 'fsel' parameter of 'last.php', allowing unauthorized access to user credentials. The payload extracts usernames and passwords from the 'user' table by manipulating the SQL query.

Description

SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL statements via the fsel parameter, as demonstrated using last.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by anonymous · textwebappsphp
https://www.exploit-db.com/exploits/631

This exploit demonstrates a SQL injection vulnerability in the 'fsel' parameter of 'last.php', allowing unauthorized access to user credentials. The payload extracts usernames and passwords from the 'user' table by manipulating the SQL query.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Unknown (likely a PHP-based forum or CMS from 2004)
No auth needed
Prerequisites: Access to the vulnerable 'last.php' endpoint
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=110019198507100&w=2

Scores

EPSS 0.0101
EPSS Percentile 59.8%

Details

Status published
Products (11)
jelsoft/vbulletin 3.0.0
jelsoft/vbulletin 3.0.0_beta_2
jelsoft/vbulletin 3.0.0_can4
jelsoft/vbulletin 3.0.0_rc4
jelsoft/vbulletin 3.0.1
jelsoft/vbulletin 3.0.2
jelsoft/vbulletin 3.0.3
jelsoft/vbulletin 3.0.4
jelsoft/vbulletin 3.0.5
jelsoft/vbulletin 3.0.6
... and 1 more
Published Dec 31, 2004
Tracked Since Feb 18, 2026