CVE-2004-0091
Last modified
CVE-2004-0091 is a vulnerability of currently unknown severity. NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter. EPSS estimates a 1.21% chance of exploitation in the next 30 days.
Description
NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in register.php for unknown versions of vBulletin allows remote attackers to inject arbitrary HTML or web script via the reg_site (or possibly regsite) parameter. NOTE: the vendor has disputed this issue, saying "There is no hidden field called 'reg_site', nor any $reg_site variable anywhere in the vBulletin 2 or vBulletin 3 source code or templates, nor has it ever existed. We can only assume that this vulnerability was found in a site running code modified from that supplied by Jelsoft.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jelsoft | Vbulletin | 3.0_beta_2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-0091?
How severe is CVE-2004-0091?
How do I fix CVE-2004-0091?
Are you affected by CVE-2004-0091?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
