vendor:
vBulletin
by:
D4rkB1t
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: vBulletin
Affected Version From: 4.0.x
Affected Version To: 4.1.2002
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested:
2011
vBulletin 4.0.x => 4.1.2 (search.php) SQL Injection Vulnerability
The vulnerability allows an attacker to perform SQL injection attacks through the search.php page in vBulletin 4.0.x to 4.1.2. The attacker can execute arbitrary SQL queries and gain unauthorized access to the database.
Mitigation:
The vendor has released a patch in vb#4.1.3. It is advised to update to the latest version to mitigate the vulnerability.