CVE-2004-0091: XSS
DISPUTED NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the regsite (or possibly regsite) parameter. NOTE: the vendor has disputed this issue, saying "There is no hidden field called 'regsite', nor any $regsite variable anywhere in the vBulletin 2 or vBulletin 3 source code or templates, nor has it ever existed. We can only assume that this vulnerability was found in a site running code modified from that supplied by Jelsoft."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0091?
The severity of CVE-2004-0091 is disputed by the vendor, but it is related to an XSS vulnerability which can allow attackers to inject arbitrary HTML or web scripts.
How do I fix CVE-2004-0091?
To fix CVE-2004-0091, you should update to a patched version of vBulletin if available, and consider implementing input validation and output encoding.
Which versions of vBulletin are affected by CVE-2004-0091?
CVE-2004-0091 specifically affects unknown versions of vBulletin including 3.0_beta_2.
What type of attack is associated with CVE-2004-0091?
CVE-2004-0091 is associated with cross-site scripting (XSS) attacks, allowing remote attackers to inject malicious scripts.
Is CVE-2004-0091 still a concern for vBulletin users?
While CVE-2004-0091 was identified a long time ago, its relevance may depend on the specific version in use and current security practices of the vBulletin installations.