📦

vbseo

Vendor: crawlability

Actively Exploited 0 CISA KEV List
PoC / Exploits 3 Code Available
Total RCEs 2 Remote Access
Total CVEs 3 Total Indexed
Avg. EPSS 14.51% Exploit Prob.
Latest CVE CVE-2012-6666 Feb 10

Security Vulnerability Index

Page 1 / 1
6.1 CVSS

vBSeo before 3.6.0PL2 allows XSS via the member.php u parameter.

EPSS: 0.86%
8.8 CVSS
CVE-2014-9463
RCE Exploit Found

functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code via the HTTP Referer header to visitormessage.php.

EPSS: 14.79%
7.5 CVSS
CVE-2012-5223
RCE Exploit Found

The proc_deutf function in includes/functions_vbseocp_abstract.php in vBSEO 3.5.0, 3.5.1, 3.5.2, 3.6.0, and earlier allows remote attackers to insert and execute arbitrary PHP code via "complex curly syntax" in the char_repl parameter, which is inserted into a regular expression that is processed by the preg_replace function with the eval switch.

EPSS: 40.53%
6.8 CVSS
CVE-2010-1077
Exploit Found

Directory traversal vulnerability in vbseo.php in Crawlability vBSEO plugin 3.1.0 for vBulletin allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the vbseourl parameter.

EPSS: 1.86%