ID

VAR-201004-0512


TITLE

vBulletin Two-Step External Link Module Cross-Site Scripting Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2010-3506

DESCRIPTION

vBulletin is an open source PHP forum program. The URL parameter submitted to the externalredirect.php page is not correctly filtered back to the user in the Two-Step External Link module used by vBulletin. The remote attacker can request a cross-site scripting attack by submitting malicious parameters, resulting in the user's browser. Execute arbitrary HTML and script code in the session. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks

Trust: 0.81

sources: CNVD: CNVD-2010-3506 // BID: 39597

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2010-3506

AFFECTED PRODUCTS

vendor:vbulletinmodel:vbulletinscope: - version: -

Trust: 0.6

vendor:vbulletinmodel:two-step external linkscope:eqversion:0

Trust: 0.3

sources: CNVD: CNVD-2010-3506 // BID: 39597

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2010-3506
value: HIGH

Trust: 0.6

CNVD: CNVD-2010-3506
severity: HIGH
baseScore: 7.1
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2010-3506

THREAT TYPE

network

Trust: 0.3

sources: BID: 39597

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 39597

EXTERNAL IDS

db:BIDid:39597

Trust: 0.9

db:CNVDid:CNVD-2010-3506

Trust: 0.6

sources: CNVD: CNVD-2010-3506 // BID: 39597

REFERENCES

url:http://www.securityfocus.com/bid/39597

Trust: 0.6

url:http://www.vbulletin.com

Trust: 0.3

url:/archive/1/510847

Trust: 0.3

sources: CNVD: CNVD-2010-3506 // BID: 39597

CREDITS

Edgard Chammas

Trust: 0.3

sources: BID: 39597

SOURCES

db:CNVDid:CNVD-2010-3506
db:BIDid:39597

LAST UPDATE DATE

2022-05-17T01:51:50.429000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2010-3506date:2010-04-20T00:00:00
db:BIDid:39597date:2010-04-20T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2010-3506date:2010-04-20T00:00:00
db:BIDid:39597date:2010-04-20T00:00:00