vendor:
vBulletin
by:
SecurityFocus
2.6
CVSS
LOW
HTML Injection
79
CWE
Product Name: vBulletin
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
Problems with vBulletin
vBulletin does not sufficiently filter potentially malicious HTML code from posted messages. As a result, when a user chooses to view a message posting that contains malicious HTML code, the code contained in the message would be executed in the browser of the vulnerable user.
Mitigation:
The vendor recommends that users do not enable HTML in messages.