Required CVE Record Information
Description
Multiple cross-site scripting (XSS) vulnerabilities in admincp/index.php in Jelsoft vBulletin 3.6.x allow remote attackers to inject arbitrary web script or HTML via (1) the prefs parameter in a buildnavprefs action or (2) the navprefs parameter in a savenavprefs action.
References 7 Total
- http://www.vbulletin.com/forum/showthread.php?postid=1256434
- secunia.com: 23011 third-party-advisory
- securityfocus.com: 21157 vdb-entry
- exchange.xforce.ibmcloud.com: vbulletin-index-admin-control-xss(30408) vdb-entry
- vupen.com: ADV-2006-4599 vdb-entry
- securityreason.com: 1903 third-party-advisory
- securityfocus.com: 20061117 XSS vBulletin 3.6.X Admin Control Painel mailing-list
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 7 Total
- http://www.vbulletin.com/forum/showthread.php?postid=1256434 x_transferred
- secunia.com: 23011 third-party-advisoryx_transferred
- securityfocus.com: 21157 vdb-entryx_transferred
- exchange.xforce.ibmcloud.com: vbulletin-index-admin-control-xss(30408) vdb-entryx_transferred
- vupen.com: ADV-2006-4599 vdb-entryx_transferred
- securityreason.com: 1903 third-party-advisoryx_transferred
- securityfocus.com: 20061117 XSS vBulletin 3.6.X Admin Control Painel mailing-listx_transferred