CVE-2006-3253
Title: Jelsoft Vbulletin Cross-Site Scripting (XSS)
XSS
Proof Of Concept
PoC Available for CVE-2006-3253
CWE Category
NVD-CWE-noinfo
Published Date
Jun 28, 2006
Modified Date
Jun 16, 2026
Exploit Status
Available
Score
2.6
CVSS v2.0
Exploit Probability (EPSS)
1.97%
Vulnerability Summary
CVE-2006-3253: Cross-site scripting (XSS) vulnerability in member.php in vBulletin 3.5.x allows remote attackers to inject arbitrary web script or HTML via the u parameter. NOTE: the vendor has disputed this report, stating that they have been unable to replicate the issue and that "the userid parameter is run through our filtering system as an unsigned integer.
Impacted Vendors
Reference Links
http://securityreason.com/securityalert/1155
http://securitytracker.com/id?1016348
http://www.osvdb.org/27508
http://www.securityfocus.com/archive/1/437817/100/0/threaded
http://www.securityfocus.com/archive/1/438364/100/100/threaded
http://www.securityfocus.com/bid/18551
https://exchange.xforce.ibmcloud.com/vulnerabilities/27261
http://securityreason.com/securityalert/1155
http://securitytracker.com/id?1016348
http://www.osvdb.org/27508
http://www.securityfocus.com/archive/1/437817/100/0/threaded
http://www.securityfocus.com/archive/1/438364/100/100/threaded
http://www.securityfocus.com/bid/18551
https://exchange.xforce.ibmcloud.com/vulnerabilities/27261
CVSS v2.0
Source Entity
[email protected]
Severity
LOW
2.6
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:N/AC:H/Au:N/C:N/I:P/A:N
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2006-3253 Exploits & PoCs (Proof Of Concept)
Exploit-DB
https://www.exploit-db.com/exploits/28076
MODIFIED
Vulnerability data updated via NVD.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
N/A
Complexity
N/A
Privileges
N/A
Interaction
NONE
CVSS Vector String
AV:N/AC:H/Au:N/C:N/I:P/A:N
Affected Stack
No specific products linked.