CVE-2001-0475: High severity Jelsoft vBulletin vulnerability
Published Jun 27, 2001
·Updated
index.php in Jelsoft vBulletin does not properly initialize a PHP variable that is used to store template information, which allows remote attackers to execute arbitrary PHP code via special characters in the templatecache parameter.
Affected Software
2 affected components
Jelsoft vBulletin<=1.1.5
Jelsoft vBulletin<=2.0_beta_2
Remediation
Event History
Jun 27, 2001
CVE Published
04:00 AM
Sep 18, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0475?
CVE-2001-0475 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2001-0475?
To fix CVE-2001-0475, upgrade Jelsoft vBulletin to a version later than 1.1.5 or 2.0_beta_2.
3
What versions of Jelsoft vBulletin are affected by CVE-2001-0475?
CVE-2001-0475 affects all vBulletin versions up to and including 1.1.5 and 2.0_beta_2.
4
What type of attack does CVE-2001-0475 enable?
CVE-2001-0475 allows remote attackers to execute arbitrary PHP code on vulnerable installations.
5
Is there a public exploit for CVE-2001-0475?
Yes, public exploits for CVE-2001-0475 are available, which demonstrate how to exploit the vulnerability.