header-logo
Suggest Exploit
vendor:
VBulletin Software
by:
5.5
CVSS
MEDIUM
Spoofing
20
CWE
Product Name: VBulletin Software
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested:

VBulletin Software Spoofing Vulnerability

A weakness has been reported to exist in the VBulletin software that may allow an attacker to spoof parts of the VBulletin interface. The issue exists due to improper validation of user-supplied data. Remote attackers may potentially exploit this issue, by convincing a VBulletin administrator to follow a specially crafted URI. The URI would contain a URI to a remote attacker owned HTML page as a value for the affected parameter of the 'index.php' script. If the administrator were to follow this link, part of the VBulletin user interface may be spoofed by the attacker.

Mitigation:

Properly validate user-supplied data and avoid following suspicious or untrusted links.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/10362/info

A weakness has been reported to exist in the VBulletin software that may allow an attacker to spoof parts of the VBulletin interface. The issue exists due to improper validation of user-supplied data.

Remote attackers may potentially exploit this issue, by convincing a VBulletin administrator to follow a specially crafted URI. The URI would contain a URI to a remote attacker owned HTML page as a value for the affected parameter of the 'index.php' script. If the administrator were to follow this link, part of the VBulletin user interface may be spoofed by the attacker.

http://forums.example.com/admincp/index.php?loc=http://www.example.com