PoC Index

CVE-2005-0511

HIGH 7.5EPSS 35.8%

misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
35.82% chance of exploitation in the next 30 days, 98th percentile
Published
2005-02-23
Updated
2024-08-07

Metasploit modules (1)

ExploitDB entries (2)

References

Related