VendorsJelsoftvbulletin3.0.10
Vulnerabilities

Jelsoft Vbulletin 3.0.10

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2006-2805
SQL injection vulnerability in VBulletin 3.0.10 allows remote attackers to execute arbitrary SQL commands via the featureid parameter.
Published 2006-06-03 · Modified
5.01 PoCEPSS 0.009
CVE-2005-4621
Cross-site scripting (XSS) vulnerability in the editavatar page in vBulletin 3.5.1 allows remote attackers to inject arbitrary web script or HTML via a URL in the remote avatar url field, in which the URL generates a parsing error, and possibly requiring a trailing extension such as .jpg.
Published 2006-01-06 · Modified
4.3EPSS 0.012