Korean
<< Back
VID 21450
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The vBulletin software has a 'memberlist.php' Cross-site Scripting Vulnerability.
vBulletin is a PHP-based Web forum, developed by Jelsoft Enterprises, that uses a MySQL database.vBulletin versions 3.0.0 RC 4 and earlier are vulnerable to cross-site scripting vulnerability, caused by a failure of the application to properly validate user-supplied input in the 'memberlist.php' script. A remote attacker could create a specially crafted URL link to the 'memberlist.php' script containing malicious script code in the 'what' variable, and then could persuade a target user to click it. Once the URL is clicked, the embedded codes would be executed in the victim's Web browser. A remote attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

* References:
http://www.osvdb.org/displayvuln.php?osvdb_id=4312
http://securitytracker.com/alerts/2004/Mar/1009440.html

* Platforms Affected:
Jelsoft Enterprises Limited, vBulletin 3.0.0RC4 and earlier
Microsoft Windows Any version
Linux Any version
Unix Any version
Recommendation Upgrade to the new version of vBulletin from the vBulletin Web Site at http://www.vbulletin.com/
Related URL CVE-2004-1824 (CVE)
Related URL 9887 (SecurityFocus)
Related URL 15495 (ISS)