CVE-2005-0511
N/A
N/A
Summary
misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://secunia.com/advisories/14326
- http://www.vbulletin.com/forum/showthread.php?postid=819562
- http://marc.info/?l=bugtraq&m=110910899415763&w=2
- http://www.securityfocus.com/bid/12622
References
- http://secunia.com/advisories/14326
- http://www.vbulletin.com/forum/showthread.php?postid=819562
- http://marc.info/?l=bugtraq&m=110910899415763&w=2
- http://www.securityfocus.com/bid/12622
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.