Korean
<< Back
VID 21360
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The vBulletin installed on the remote web server, according to its version number, has 'newreply.php' and 'newthread.php' Cross-Site Scripting Vulnerabilities.
vBulletin is a PHP-based Web forum developed by Jelsoft Enterprises that uses a MySQL database. vBulletin versions 3.0.1 and earlier are vulnerable to cross-site scripting vulnerability, caused by a improper filtering of user-supplied input in the 'newreply.php' and 'newthread.php' script. A remote attacker could create a specially crafted URL link to these scripts containing malicious script code, and then could persuade a target user to click it. Once the URL is clicked, the embedded codes would be executed in the victim's Web browser. A remote attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

* Note: This check solely relied on the version number of the remote vBulletin to assess this vulnerability, so this might be a false positive.

* References:
http://www.osvdb.org/displayvuln.php?osvdb_id=7256

* Platforms Affected:
Jelsoft Enterprises Limited, vBulletin 3.0.1 and earlier
Any operating system Any version
Recommendation No upgrade or patch available as of September 2004.

Upgrade to the fixed version of vBulletin, when new fixed version becomes available from the vBulletin Download page at http://www.vbulletin.com/download.php
Related URL CVE-2004-0620 (CVE)
Related URL 10602 (SecurityFocus)
Related URL 16502 (ISS)