Unrated severityNVD Advisory· Published Feb 8, 2011· Updated Apr 29, 2026
CVE-2011-0526
CVE-2011-0526
Description
Cross-site scripting (XSS) vulnerability in index.php in Vanilla Forums before 2.0.17 allows remote attackers to inject arbitrary web script or HTML via the Target parameter in a /entry/signin action.
Affected products
8cpe:2.3:a:vanillaforums:vanilla:*:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:vanillaforums:vanilla:*:*:*:*:*:*:*:*range: <=2.0.16
- cpe:2.3:a:vanillaforums:vanilla:2.0.9:*:*:*:*:*:*:*
- cpe:2.3:a:vanillaforums:vanilla:2.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:vanillaforums:vanilla:2.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:vanillaforums:vanilla:2.0.12:*:*:*:*:*:*:*
- cpe:2.3:a:vanillaforums:vanilla:2.0.13:*:*:*:*:*:*:*
- cpe:2.3:a:vanillaforums:vanilla:2.0.14:*:*:*:*:*:*:*
- cpe:2.3:a:vanillaforums:vanilla:2.0.15:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- openwall.com/lists/oss-security/2011/01/27/2nvdExploit
- openwall.com/lists/oss-security/2011/01/27/5nvdExploit
- www.osvdb.org/70677nvdExploit
- yehg.net/lab/pr0js/advisories/%5Bvanilla_forums-2.0.16%5D_cross_site_scriptingnvdExploit
- secunia.com/advisories/43074nvdVendor Advisory
- www.vanillaforums.org/discussion/14397/vanilla-2.0.17-releasednvd
News mentions
0No linked articles in our index yet.