info
discussion
exploit
solution
references
vBulletin 'adminlog.php' Request Logging HTML Injection Vulnerability
References:
vBulletin 3.7.2 PL1 and 3.6.10 PL3 Released
(vBulletin)
vBulletin Homepage
(vBulletin)
XSS in admin logs - vBulletin 3.7.2 and lower, vBulletin 3.6.10 PL2 and lower
("Jessica Hope"
)
Privacy Statement
Copyright 2010, SecurityFocus