CVE-2005-0429: Code Injection
Published Feb 15, 2005
·Updated
Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showforumusers is enabled, allows remote attackers to execute inject arbitrary PHP commands via the comma parameter.
Affected Software
5 affected components
Jelsoft vBulletin=3.0
Jelsoft vBulletin=3.0.1
Jelsoft vBulletin=3.0.2
Jelsoft vBulletin=3.0.3
Jelsoft vBulletin=3.0.4
Event History
Feb 15, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0429?
CVE-2005-0429 has a high severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2005-0429?
To fix CVE-2005-0429, upgrade your vBulletin installation to version 3.0.5 or later.
3
Which versions of vBulletin are affected by CVE-2005-0429?
CVE-2005-0429 affects vBulletin versions 3.0 through 3.0.4.
4
What type of vulnerability is CVE-2005-0429?
CVE-2005-0429 is a direct code injection vulnerability.
5
What configuration increases the risk associated with CVE-2005-0429?
Enabling the showforumusers option increases the risk of exploitation for CVE-2005-0429.