Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-46fc-9xfj-r45q

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

member2.php in vBulletin 2.2.9 and earlier does not properly restrict the $perpage variable to be an integer, which causes an error message to be reflected back to the user without quoting, which facilitates cross-site scripting (XSS) and possibly other attacks.

member2.php in vBulletin 2.2.9 and earlier does not properly restrict the $perpage variable to be an integer, which causes an error message to be reflected back to the user without quoting, which facilitates cross-site scripting (XSS) and possibly other attacks.

EPSS

Процентиль: 64%
0.00479
Низкий

Связанные уязвимости

nvd
больше 22 лет назад

member2.php in vBulletin 2.2.9 and earlier does not properly restrict the $perpage variable to be an integer, which causes an error message to be reflected back to the user without quoting, which facilitates cross-site scripting (XSS) and possibly other attacks.

EPSS

Процентиль: 64%
0.00479
Низкий