CVE Database
/

CVE-2006-2335

Back to search

CVE-2006-2335

Published: May 12, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Jelsoft vBulletin accepts uploads of Cascading Style Sheets (CSS) and processes them in a way that allows remote authenticated administrators to gain shell access by uploading a CSS file that contains PHP code, then selecting the file via the style chooser, which causes the PHP code to be executed. NOTE: the vendor was unable to reproduce this issue in 3.5.x. NOTE: this issue might be due to direct static code injection.

VendorProductVersions

n/a

n/a

affected
n/a

References

20060506 vbulletin security Alert
mailing-list
x_refsource_BUGTRAQ
20060511 Re: vbulletin security Alert
mailing-list
x_refsource_BUGTRAQ

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now