CVE-2004-0091

NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter. NOTE: the vendor has disputed this issue, saying "There is no hidden field called 'reg_site', nor any $reg_site variable anywhere in the vBulletin 2 or vBulletin 3 source code or templates, nor has it ever existed. We can only assume that this vulnerability was found in a site running code modified from that supplied by Jelsoft.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jelsoft:vbulletin:3.0_beta_2:*:*:*:*:*:*:*

History

20 Nov 2024, 23:47

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=107462349324945&w=2 - () http://marc.info/?l=bugtraq&m=107462349324945&w=2 -
References () http://marc.info/?l=vuln-dev&m=107462499927040&w=2 - () http://marc.info/?l=vuln-dev&m=107462499927040&w=2 -
References () http://marc.info/?l=vuln-dev&m=107478592401619&w=2 - () http://marc.info/?l=vuln-dev&m=107478592401619&w=2 -
References () http://marc.info/?l=vuln-dev&m=107488880317647&w=2 - () http://marc.info/?l=vuln-dev&m=107488880317647&w=2 -
References () http://securitytracker.com/id?1008780 - () http://securitytracker.com/id?1008780 -

07 Nov 2023, 01:56

Type Values Removed Values Added
Summary ** DISPUTED ** NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter. NOTE: the vendor has disputed this issue, saying "There is no hidden field called 'reg_site', nor any $reg_site variable anywhere in the vBulletin 2 or vBulletin 3 source code or templates, nor has it ever existed. We can only assume that this vulnerability was found in a site running code modified from that supplied by Jelsoft." NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter. NOTE: the vendor has disputed this issue, saying "There is no hidden field called 'reg_site', nor any $reg_site variable anywhere in the vBulletin 2 or vBulletin 3 source code or templates, nor has it ever existed. We can only assume that this vulnerability was found in a site running code modified from that supplied by Jelsoft.

Information

Published : 2004-02-17 05:00

Updated : 2024-11-20 23:47


NVD link : CVE-2004-0091

Mitre link : CVE-2004-0091

CVE.ORG link : CVE-2004-0091


JSON object : View

Products Affected

jelsoft

  • vbulletin