vendor:
vBulletin
by:
MaXe
7,5
CVSS
HIGH
Persistent Cross Site Scripting
79
CWE
Product Name: vBulletin
Affected Version From: 4.0.8 PL1
Affected Version To: 4.0.8 PL1
Patch Exists: YES
Related CWE: N/A
CPE: vbulletin:vbulletin
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows and Linux (Server) + IE6 (Client)
2010
vBulletin 4.0.8 PL1 – XSS Filter Bypass within Profile Customization
vBulletin is prone to a Persistent Cross Site Scripting vulnerability within the Profile Customization feature. If this feature is not enabled the vulnerability does not exist and the installation of vBulletin is thereby secure. Within the profile customization fields, it is possible to enter colour codes, rgb codes and even images. The image url() function does not sanitize user input in a sufficient way causing vBulletin to be vulnerable to XSS attacks. With the previous patch for vBulletin 4.0.8 PL1, most attacks were disabled however it is possible to bypass this filter and inject data which is then executed effectively against though not limited to Internet Explorer 6.
Mitigation:
Update vBulletin to version: 4.0.8 PL2