CVE-2006-0080: XSS
Cross-site scripting (XSS) vulnerability in vBulletin 3.5.2, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the title of an event, which is not properly filtered by (1) calendar.php and (2) reminder.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0080?
CVE-2006-0080 is categorized as a cross-site scripting (XSS) vulnerability, which can lead to significant security risks.
How do I fix CVE-2006-0080?
To fix CVE-2006-0080, upgrade to the latest version of vBulletin that properly mitigates the XSS vulnerabilities.
Which versions of vBulletin are affected by CVE-2006-0080?
CVE-2006-0080 affects vBulletin version 3.5.2 and possibly earlier versions.
Can CVE-2006-0080 be exploited remotely?
Yes, remote attackers can exploit CVE-2006-0080 to inject arbitrary web scripts or HTML.
What components of vBulletin are vulnerable in CVE-2006-0080?
In CVE-2006-0080, the vulnerable components are calendar.php and reminder.php, which do not properly filter input.