VBulletin is prone to a remote denial-of-service vulnerability.
Credit:
The original article can be found at: http://www.securityfocus.com/bid/20581
Vulnerable Systems:
* VBulletin VBulletin 3.5.4
* VBulletin VBulletin 3.5.3
* VBulletin VBulletin 3.5.2
* VBulletin VBulletin 3.5.1
* VBulletin VBulletin 3.0.15
* VBulletin VBulletin 3.0.14
* VBulletin VBulletin 3.0.12
* VBulletin VBulletin 3.0.11
* VBulletin VBulletin 3.0.10
* VBulletin VBulletin 3.0.9
* VBulletin VBulletin 3.0.8
* VBulletin VBulletin 3.0.7
* VBulletin VBulletin 3.0.6
* VBulletin VBulletin 3.0.5
* VBulletin VBulletin 3.0.4
* VBulletin VBulletin 3.0.3
* VBulletin VBulletin 3.0.2
* VBulletin VBulletin 3.0.1
* VBulletin VBulletin 3.0 Gamma
* VBulletin VBulletin 3.0 beta 7
* VBulletin VBulletin 3.0 beta 6
* VBulletin VBulletin 3.0 beta 5
* VBulletin VBulletin 3.0 beta 4
* VBulletin VBulletin 3.0 beta 3
* VBulletin VBulletin 3.0 beta 2
* VBulletin VBulletin 3.0
* VBulletin VBulletin 2.3.8
* VBulletin VBulletin 2.3.4
* VBulletin VBulletin 2.3.3
* VBulletin VBulletin 2.3.2
* VBulletin VBulletin 2.3 .0
* VBulletin VBulletin 2.2.9
* VBulletin VBulletin 2.2.8
* VBulletin VBulletin 2.2.7
* VBulletin VBulletin 2.2.6
* VBulletin VBulletin 2.2.5
* VBulletin VBulletin 2.2.4
* VBulletin VBulletin 2.2.3
* VBulletin VBulletin 2.2.2
* VBulletin VBulletin 2.2.1
* VBulletin VBulletin 2.2 .0
* VBulletin VBulletin 2.0.3
* VBulletin VBulletin 2.0 rc 3
* VBulletin VBulletin 2.0 rc 2
An attacker can exploit this issue to crash the affected application, denying service to legitimate users.
VBulletin 3.6.0 and prior versions are vulnerable to this issue.
Vendor Status:
vBulletin as issued an update for this vulnerablity
Patch Availability:
https://www.vbulletin.com/order/index.php
Disclosure Timeline:
Initial Release Oct 17 2006
Please enable JavaScript to view the comments powered by Disqus.
blog comments powered by