CVE-2005-0511 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 35.8% (pctl 98)
Patch early
A public exploit exists.
Description
misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 35.82% — more likely to be exploited than 98% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-02-21 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| jelsoft | vbulletin |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | vBulletin - 'misc.php' Template Name Arbitrary Code Execution (Metasploit) | 2010-07-25 |
| exploit-db | vBulletin 3.0.6 - PHP Code Injection | 2005-02-22 |
References
- http://marc.info/?l=bugtraq&m=110910899415763&w=2
- http://secunia.com/advisories/14326
- http://www.securityfocus.com/bid/12622
- http://www.vbulletin.com/forum/showthread.php?postid=819562
- http://marc.info/?l=bugtraq&m=110910899415763&w=2
- http://secunia.com/advisories/14326
- http://www.securityfocus.com/bid/12622
- http://www.vbulletin.com/forum/showthread.php?postid=819562
→ the Explorer · watch your stack · NVD