CVE-2005-3023: XSS
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) announcement.php, (2) admincalendar.php, (3) bbcode.php, (4) cronadmin.php, (5) email.php, (6) faq.php, (7) forum.php, (8) image.php, (9) language.php, (10) ranks.php, (11) replacement.php, (12) replacement.php, (13) template.php, (14) template.php, (15) usergroup.php, or (16) usertitle.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3023?
The severity of CVE-2005-3023 is classified as high due to its potential for exploitation via cross-site scripting.
How do I fix CVE-2005-3023?
To fix CVE-2005-3023, upgrade to vBulletin version 3.0.10 or later, which addresses the identified XSS vulnerabilities.
Which versions are affected by CVE-2005-3023?
CVE-2005-3023 affects vBulletin versions 3.0.9 and earlier, along with several older versions.
What types of vulnerabilities does CVE-2005-3023 include?
CVE-2005-3023 includes multiple cross-site scripting (XSS) vulnerabilities that allow attackers to inject arbitrary scripts.
How can CVE-2005-3023 impact my website?
Exploiting CVE-2005-3023 can allow attackers to execute malicious scripts in the context of users accessing the affected website.