CVE-2006-4272
Last modified
CVE-2006-4272 is a vulnerability of currently unknown severity. Jelsoft vBulletin 3.5.4 allows remote attackers to register multiple arbitrary users and cause a denial of service (resource consumption) via a large number of requests to register.php. NOTE: the vendor has disputed this vulnerability, stating "If you have the CAPTCHA enabled then the registrations wont even go through. EPSS estimates a 1.47% chance of exploitation in the next 30 days.
Description
Jelsoft vBulletin 3.5.4 allows remote attackers to register multiple arbitrary users and cause a denial of service (resource consumption) via a large number of requests to register.php. NOTE: the vendor has disputed this vulnerability, stating "If you have the CAPTCHA enabled then the registrations wont even go through. ... if you are talking about the flood being allowed in the first place then surely this is something that should be handled at the server level.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jelsoft | Vbulletin | 3.5.4 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-4272?
How severe is CVE-2006-4272?
How do I fix CVE-2006-4272?
Are you affected by CVE-2006-4272?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
