CVE-2005-0429 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 1.9% (pctl 79)
Patch early
A public exploit exists.
Description
Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showforumusers is enabled, allows remote attackers to execute inject arbitrary PHP commands via the comma parameter.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
| EPSS | 1.93% — more likely to be exploited than 79% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-05-02 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| jelsoft | vbulletin |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | vBulletin 3.0.4 - 'forumdisplay.php' Code Execution (2) | 2005-02-15 |
| exploit-db | vBulletin 3.0.4 - 'forumdisplay.php' Code Execution (1) | 2005-02-14 |
References
→ the Explorer · watch your stack · NVD