CVE-2007-0830
Last modified
CVE-2007-0830 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in the Admin Control Panel (AdminCP) in Jelsoft vBulletin 3.6.4 allow remote authenticated administrators to inject arbitrary web script or HTML via unspecified vectors related to the (1) User Group Manager, (2) User Rank Manager, (3) User Title Manager, (4) BB Code Manager, (5) Attachment Manager, (6) Calendar Manager, and (7) Forums & Moderators functions. NOTE: the vendor disputes this issue, stating that modifying HTML is an intended privilege of an administrator. EPSS estimates a 0.87% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the Admin Control Panel (AdminCP) in Jelsoft vBulletin 3.6.4 allow remote authenticated administrators to inject arbitrary web script or HTML via unspecified vectors related to the (1) User Group Manager, (2) User Rank Manager, (3) User Title Manager, (4) BB Code Manager, (5) Attachment Manager, (6) Calendar Manager, and (7) Forums & Moderators functions. NOTE: the vendor disputes this issue, stating that modifying HTML is an intended privilege of an administrator. NOTE: it is possible that this issue overlaps CVE-2006-6040
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jelsoft | Vbulletin | 3.6.4 |
References
- http://secunia.com/advisories/24085Vendor Advisory
- http://secunia.com/advisories/24085Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-0830?
How severe is CVE-2007-0830?
How do I fix CVE-2007-0830?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-0824PHP remote file inclusion vulnerability in inhalt.php in Lig…
- CVE-2007-0825FlashFXP 3.4.0 build 1145 allows remote servers to cause a d…
- CVE-2007-0826SQL injection vulnerability in forum.asp in Kisisel Site 200…
- CVE-2007-0827The Alibaba Alipay PTA Module ActiveX control (PTA.DLL) allo…
- CVE-2007-0828PHP remote file inclusion vulnerability in affichearticles.p…
- CVE-2007-0829avast! Server Edition before 4.7.726 does not demand a passw…
- CVE-2007-0831Multiple PHP remote file inclusion vulnerabilities in Atsphp…
- CVE-2007-0832VMware Workstation 5.5.3 34685 does not immediately change t…
- CVE-2007-0833VMware Workstation 5.5.3 34685, when the "Enable copy and pa…
- CVE-2007-0834Cross-site scripting (XSS) vulnerability in FlashChat 4.7.8 …
- CVE-2007-0835admin.php in Coppermine Photo Gallery 1.4.10, and possibly e…
- CVE-2007-0836admin.php in Coppermine Photo Gallery 1.4.10, and possibly e…
Are you affected by CVE-2007-0830?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
