CVE-2011-5251: Input Validation
Published Dec 31, 2012
·Updated
Open redirect vulnerability in forum/login.php in vBulletin 4.1.3 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter in a lostpw action.
Affected Software
13 affected components
vBulletin vBulletin<=4.1.3
vBulletin vBulletin=4.0.0
vBulletin vBulletin=4.0.1
vBulletin vBulletin=4.0.2
vBulletin vBulletin=4.0.3
vBulletin vBulletin=4.0.4
vBulletin vBulletin=4.0.5
vBulletin vBulletin=4.0.6
vBulletin vBulletin=4.0.7
vBulletin vBulletin=4.0.8
vBulletin vBulletin=4.1
vBulletin vBulletin=4.1.1
vBulletin vBulletin=4.1.2
Event History
Dec 31, 2012
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-5251?
CVE-2011-5251 has a medium severity rating as it allows for phishing attacks through an open redirect.
2
How do I fix CVE-2011-5251?
To fix CVE-2011-5251, upgrade your vBulletin installation to version 4.1.4 or later.
3
What type of vulnerability is CVE-2011-5251?
CVE-2011-5251 is an open redirect vulnerability that can redirect users to arbitrary websites.
4
Who is affected by CVE-2011-5251?
CVE-2011-5251 affects all vBulletin versions up to and including 4.1.3.
5
Can CVE-2011-5251 lead to other types of attacks?
Yes, CVE-2011-5251 can lead to phishing and potentially other attacks by redirecting users to malicious sites.