CVE-2005-3020

vBulletin < 3.0.9 - Cross-Site Scripting via Multiple Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 6 public exploits for CVE-2005-3020. PoCs published by [email protected].

AI-analyzed exploit summary The provided text describes multiple XSS vulnerabilities in vBulletin due to insufficient input sanitization. It includes example URLs demonstrating how arbitrary script code could be executed in the context of the affected site.

Description

Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to css.php, (2) redirect parameter to index.php, (3) email parameter to user.php, (4) goto parameter to language.php, (5) orderby parameter to modlog.php, and the (6) hex, (7) rgb, or (8) expandset parameter to template.php.

Exploits (6)

exploitdb WRITEUP VERIFIED
by [email protected] · textwebappsphp
https://www.exploit-db.com/exploits/26280

The provided text describes multiple XSS vulnerabilities in vBulletin due to insufficient input sanitization. It includes example URLs demonstrating how arbitrary script code could be executed in the context of the affected site.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Theoretical
Target: vBulletin (version not specified)
No auth needed
Prerequisites: Access to the vulnerable vBulletin instance · Ability to craft malicious URLs with XSS payloads
MITRE ATT&CK
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by [email protected] · textwebappsphp
https://www.exploit-db.com/exploits/26283

The provided text describes multiple XSS vulnerabilities in vBulletin due to insufficient input sanitization in the admincp/template.php script. The writeup includes example URLs demonstrating the vulnerabilities but does not contain executable exploit code.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Theoretical
Target: vBulletin (version not specified)
Auth required
Prerequisites: Access to admincp/template.php · Victim interaction required
MITRE ATT&CK
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by [email protected] · textwebappsphp
https://www.exploit-db.com/exploits/26282

The provided text describes a cross-site scripting (XSS) vulnerability in vBulletin, where user-supplied input is not properly sanitized. The example URL demonstrates how an attacker could inject arbitrary script code via the 'orderby' parameter in the admin control panel.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: vBulletin (version not specified)
Auth required
Prerequisites: Access to the admin control panel · User interaction required to trigger the XSS
MITRE ATT&CK
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by [email protected] · textwebappsphp
https://www.exploit-db.com/exploits/26281

The provided text describes a cross-site scripting (XSS) vulnerability in vBulletin, specifically in the admincp/language.php endpoint. It lacks executable exploit code but details the vulnerability and potential impact.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Theoretical
Target: vBulletin (version not specified)
Auth required
Prerequisites: Access to the admin control panel · User interaction or admin privileges to trigger the payload
MITRE ATT&CK
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by [email protected] · textwebappsphp
https://www.exploit-db.com/exploits/26279

The provided text describes multiple XSS vulnerabilities in vBulletin due to insufficient input sanitization. It includes example URLs demonstrating the vulnerabilities but does not contain executable exploit code.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Theoretical
Target: vBulletin (version not specified)
No auth needed
Prerequisites: Access to the vulnerable vBulletin instance
MITRE ATT&CK
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by [email protected] · textwebappsphp
https://www.exploit-db.com/exploits/26278

The provided text describes a cross-site scripting (XSS) vulnerability in vBulletin, where user-supplied input is not properly sanitized. The example URL demonstrates how an attacker could inject arbitrary script code into the browser of an unsuspecting user.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: vBulletin
No auth needed
Prerequisites: Access to the target vBulletin instance
MITRE ATT&CK
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Exploit, Patch, Vendor Advisory x_refsource_misc
http://morph3us.org/advisories/20050917-vbulletin-3.0.8.txt
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/22324
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/14874
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=112715150320677&w=2
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/16873/

Scores

EPSS 0.0183
EPSS Percentile 76.7%

Details

Status published
Products (35)
jelsoft/vbulletin 1.0.1
jelsoft/vbulletin 2.0.3
jelsoft/vbulletin 2.0_rc2
jelsoft/vbulletin 2.0_rc3
jelsoft/vbulletin 2.2.0
jelsoft/vbulletin 2.2.1
jelsoft/vbulletin 2.2.2
jelsoft/vbulletin 2.2.3
jelsoft/vbulletin 2.2.4
jelsoft/vbulletin 2.2.5
... and 25 more
Published Sep 21, 2005
Tracked Since Feb 18, 2026