CVE-2006-4272
Last modified
CVE-2006-4272 is a vulnerability of currently unknown severity. Jelsoft vBulletin 3.5.4 allows remote attackers to register multiple arbitrary users and cause a denial of service (resource consumption) via a large number of requests to register.php. NOTE: the vendor has disputed this vulnerability, stating "If you have the CAPTCHA enabled then the registrations wont even go through. EPSS estimates a 1.47% chance of exploitation in the next 30 days.
Description
Jelsoft vBulletin 3.5.4 allows remote attackers to register multiple arbitrary users and cause a denial of service (resource consumption) via a large number of requests to register.php. NOTE: the vendor has disputed this vulnerability, stating "If you have the CAPTCHA enabled then the registrations wont even go through. ... if you are talking about the flood being allowed in the first place then surely this is something that should be handled at the server level.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jelsoft | Vbulletin | 3.5.4 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-4272?
How severe is CVE-2006-4272?
How do I fix CVE-2006-4272?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-4266Symantec Norton Personal Firewall 2006 9.1.0.33, and possibl…
- CVE-2006-4267Multiple SQL injection vulnerabilities in CubeCart 3.0.11 an…
- CVE-2006-4268Multiple cross-site scripting (XSS) vulnerabilities in CubeC…
- CVE-2006-4269PHP remote file inclusion vulnerability in admin.x-shop.php …
- CVE-2006-4270PHP remote file inclusion vulnerability in mambelfish.class.…
- CVE-2006-4271PHP remote file inclusion vulnerability in install/upgrade_3…
- CVE-2006-4273Cross-site scripting (XSS) vulnerability in Jelsoft vBulleti…
- CVE-2006-4274Rejected reason: Unknown vulnerability in Microsoft PowerPoi…
- CVE-2006-4275PHP remote file inclusion vulnerability in catalogshop.php i…
- CVE-2006-4276PHP remote file inclusion vulnerability in Tutti Nova 1.6 an…
- CVE-2006-4277Multiple PHP remote file inclusion vulnerabilities in Tutti …
- CVE-2006-4278PHP remote file inclusion vulnerability in includes/layout/p…
Are you affected by CVE-2006-4272?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
