peter bassill · operator
$ cve CVE-2005-0511 JSON

CVE-2005-0511 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 35.8% (pctl 98)

Patch early

A public exploit exists.

Description

misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS35.82% — more likely to be exploited than 98% of all CVEs
On CISA KEVno
Public exploityes
Published2005-02-21
Last modified2026-06-16

Affected (1)

VendorProduct
jelsoftvbulletin

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD