CVE-2008-3184: XSS
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.6.10 PL2 and earlier, and 3.7.2 and earlier 3.7.x versions, allow remote attackers to inject arbitrary web script or HTML via (1) the PATHINFO (PHPSELF) or (2) the do parameter, as demonstrated by requests to upload/admincp/faq.php. NOTE: this issue can be leveraged to execute arbitrary PHP code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3184?
CVE-2008-3184 is categorized as a critical vulnerability due to the potential for remote code execution via cross-site scripting.
How do I fix CVE-2008-3184?
To resolve CVE-2008-3184, you should upgrade to vBulletin 3.6.10 PL3 or higher, or 3.7.2 PL1 or higher.
What types of attacks can exploit CVE-2008-3184?
CVE-2008-3184 can be exploited through cross-site scripting attacks that allow an attacker to inject malicious scripts.
Which versions of vBulletin are affected by CVE-2008-3184?
CVE-2008-3184 affects vBulletin versions 3.6.10 PL2 and earlier, as well as all versions of 3.7.2 and earlier in the 3.7.x series.
What are the common impacts of CVE-2008-3184 exploitation?
Exploitation of CVE-2008-3184 can lead to unauthorized access, data theft, or manipulation of user sessions.