index.php in Jelsoft vBulletin does not properly initialize a PHP variable that is used to store template information, which allows remote attackers to execute arbitrary PHP code via special characters in the templatecache parameter.
Link | Tags |
---|---|
http://www.vbulletin.com/forum/showthread.php?s=b20af207b5b908ecf7a4ecf56fbe3cd3&threadid=10839 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/6237 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2001-03/0180.html | mailing list exploit patch vendor advisory |
http://www.securityfocus.com/bid/2474 | vdb entry vendor advisory |