CVE Database
/

CVE-2004-0091

Back to search

CVE-2004-0091

Published: Jan 22, 2004

Modified: Aug 8, 2024

PUBLISHED

Description

NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter. NOTE: the vendor has disputed this issue, saying "There is no hidden field called 'reg_site', nor any $reg_site variable anywhere in the vBulletin 2 or vBulletin 3 source code or templates, nor has it ever existed. We can only assume that this vulnerability was found in a site running code modified from that supplied by Jelsoft.

VendorProductVersions

n/a

n/a

affected
n/a

References

20040120 vBulletin Security Vulnerability
mailing-list
x_refsource_VULN-DEV
1008780
vdb-entry
x_refsource_SECTRACK
20040120 vBulletin Security Vulnerability
mailing-list
x_refsource_BUGTRAQ
20040123 RE: vBulletin Security Vulnerability
mailing-list
x_refsource_VULN-DEV
20040120 Re: vBulletin Security Vulnerability
mailing-list
x_refsource_VULN-DEV

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now