First published: Wed Jun 27 2001(Updated: )
index.php in Jelsoft vBulletin does not properly initialize a PHP variable that is used to store template information, which allows remote attackers to execute arbitrary PHP code via special characters in the templatecache parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jelsoft vBulletin | <=1.1.5 | |
Jelsoft vBulletin | <=2.0_beta_2 |
http://www.vbulletin.com/forum/showthread.php?s=b20af207b5b908ecf7a4ecf56fbe3cd3&threadid=10839
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.