CVE-2005-0511
vBulletin <3.0.6 - RCE
Title source: llmDescription
misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.
Exploits (3)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubywebappsphp
https://www.exploit-db.com/exploits/16896
metasploit
WORKING POC
EXCELLENT
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/php_vbulletin_template.rb
Scores
EPSS
0.8221
EPSS Percentile
99.2%
Classification
Status
draft
Affected Products (29)
jelsoft/vbulletin
jelsoft/vbulletin
jelsoft/vbulletin
jelsoft/vbulletin
jelsoft/vbulletin
jelsoft/vbulletin
jelsoft/vbulletin
jelsoft/vbulletin
jelsoft/vbulletin
jelsoft/vbulletin
jelsoft/vbulletin
jelsoft/vbulletin
jelsoft/vbulletin
jelsoft/vbulletin
jelsoft/vbulletin
... and 14 more
Timeline
Published
Feb 21, 2005
Tracked Since
Feb 18, 2026