VYPR
Unrated severityNVD Advisory· Published Feb 21, 2005· Updated Apr 16, 2026

CVE-2005-0511

CVE-2005-0511

Description

misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.

Affected products

29
  • Jelsoft/Vbulletin29 versions
    cpe:2.3:a:jelsoft:vbulletin:2.0:*:*:*:*:*:*:*+ 28 more
    • cpe:2.3:a:jelsoft:vbulletin:2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:jelsoft:vbulletin:2.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:jelsoft:vbulletin:2.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:jelsoft:vbulletin:2.0_beta_2:*:*:*:*:*:*:*
    • cpe:2.3:a:jelsoft:vbulletin:2.0_beta_3:*:*:*:*:*:*:*
    • cpe:2.3:a:jelsoft:vbulletin:2.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:jelsoft:vbulletin:2.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:jelsoft:vbulletin:2.2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:jelsoft:vbulletin:2.2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:jelsoft:vbulletin:2.2.4:*:*:*:*:*:*:*
    • cpe:2.3:a:jelsoft:vbulletin:2.2.5:*:*:*:*:*:*:*
    • cpe:2.3:a:jelsoft:vbulletin:2.2.6:*:*:*:*:*:*:*
    • cpe:2.3:a:jelsoft:vbulletin:2.2.7:*:*:*:*:*:*:*
    • cpe:2.3:a:jelsoft:vbulletin:2.2.8:*:*:*:*:*:*:*
    • cpe:2.3:a:jelsoft:vbulletin:2.2.9_can:*:*:*:*:*:*:*
    • cpe:2.3:a:jelsoft:vbulletin:2.3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:jelsoft:vbulletin:2.3.3:*:*:*:*:*:*:*
    • cpe:2.3:a:jelsoft:vbulletin:2.3.4:*:*:*:*:*:*:*
    • cpe:2.3:a:jelsoft:vbulletin:3.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:jelsoft:vbulletin:3.0.0_beta_2:*:*:*:*:*:*:*
    • cpe:2.3:a:jelsoft:vbulletin:3.0.0_can4:*:*:*:*:*:*:*
    • cpe:2.3:a:jelsoft:vbulletin:3.0.0_rc4:*:*:*:*:*:*:*
    • cpe:2.3:a:jelsoft:vbulletin:3.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:jelsoft:vbulletin:3.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:jelsoft:vbulletin:3.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:jelsoft:vbulletin:3.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:jelsoft:vbulletin:3.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:jelsoft:vbulletin:3.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:jelsoft:vbulletin:3.0_beta_2:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.