LOW
Multiple cross-site scripting (XSS) vulnerabilities in the Admin Control Panel (AdminCP) in Jelsoft vBulletin 3.6.4 allow remote authenticated administrators to inject arbitrary web script or HTML via unspecified vectors related to the (1) User Group Manager, (2) User Rank Manager, (3) User Title Manager, (4) BB Code Manager, (5) Attachment Manager, (6) Calendar Manager, and (7) Forums & Moderators functions
Published Feb 7, 2007
3.5
LOWCVSS 2.0
EPSS 0.91%
Description
Affected products
Remediation
Metrics
References (5)
Change history (0)
No recorded changes yet.