Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2005-0511

EPSS 82.21% · P99
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2005-0511

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
vBulletin misc.php template名远程代码注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
vBulletin是一款开放源代码PHP论坛程序。 vBulletin对用户提交的template名输入缺少充分过滤,远程攻击者可以利用这个漏洞进行代码注入攻击,以Web进程的权限执行任意命令。 在当Add Template Name in HTML Comments功能开启的时候,用户可以提交恶意代码给template变量值,从而执行任意代码或获得敏感信息。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2005-0511

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2005-0511

登录查看更多情报信息。

Same Patch Batch · n/a · 2005-02-23 · 16 CVEs total

CVE-2003-1086pMachine Free和pMachine Pro pm/lib.inc.php远程代码执行漏洞
CVE-2004-0465OpenConnect WebConnect多个远程漏洞
CVE-2004-0466OpenConnect WebConnect多个远程漏洞
CVE-2005-0512Mamboo Tar文件远程文件包含漏洞
CVE-2005-0513Pmachine Pro Email This Entry Mail_autocheck.PHP远程文件包含漏洞
CVE-2005-0514Verity Ultraseek搜索请求跨站脚本攻击漏洞
CVE-2005-0516Twiki ImageGalleryPlugin远程攻击漏洞
CVE-2005-0517PeerFTP_5不安全的密码存储漏洞
CVE-2005-0518eXeem Exeem注册表 键敏感信息泄露漏洞
CVE-2005-0519ArGoSoft FTP服务器快捷方式文件上传漏洞
CVE-2005-0520ArGoSoft FTP Server Site Copy快捷方式文件上传漏洞
CVE-2005-0521SendLink data.eat文件敏感信息泄露漏洞
CVE-2005-0522LionMax软件Chat Anywhere不安全的密码储存漏洞
CVE-2005-0523ProZilla格式化字符串漏洞
CVE-2005-0526PBLang 4.65多个跨站脚本攻击漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2005-0511

No comments yet


Leave a comment