Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 3.5.4 and 3.6.0...
Vulnerability Description
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 3.5.4 and 3.6.0 allows remote attackers to inject arbitrary web script or HTML by uploading an attachment with a .pdf extension that contains JavaScript, which is processed as script by Microsoft Internet Explorer 6.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-4273
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.osvdb.org/27778
- http://www.securityfocus.com/archive/1/442488/100/200/threaded
- http://archives.neohapsis.com/archives/bugtraq/2006-08/0074.html
- http://archives.neohapsis.com/archives/bugtraq/2006-08/0082.html
- http://www.securityfocus.com/bid/19334
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28239
More from jelsoft
View All →Affected Vendor
jelsoft
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.