CVE-2006-4273: XSS
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 3.5.4 and 3.6.0 allows remote attackers to inject arbitrary web script or HTML by uploading an attachment with a .pdf extension that contains JavaScript, which is processed as script by Microsoft Internet Explorer 6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4273?
CVE-2006-4273 is rated as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2006-4273?
To mitigate CVE-2006-4273, users should upgrade to a patched version of vBulletin that addresses this vulnerability.
What versions of vBulletin are affected by CVE-2006-4273?
CVE-2006-4273 affects vBulletin versions 3.5.4 and 3.6.0.
What kind of attack can be executed using CVE-2006-4273?
CVE-2006-4273 allows an attacker to execute arbitrary web scripts or HTML through a crafted PDF attachment.
Who can exploit CVE-2006-4273?
CVE-2006-4273 can be exploited by remote attackers who upload malicious PDF files containing JavaScript.