Medium severity6.1NVD Advisory· Published Jan 11, 2018· Updated Jun 16, 2026
CVE-2012-6682
CVE-2012-6682
Description
Cross-site scripting (XSS) vulnerability in downloads/actions/editdownload.php in the DragonByte Technologies vBDownloads module 1.3.2 and earlier for vBulletin allows remote attackers to inject arbitrary web script or HTML via the mirrors[] parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <=1.3.2
- cpe:2.3:a:dragonbyte-tech:vbdownloads_module:1.3.2:*:*:*:*:vbulletin:*:*
Patches
Vulnerability mechanics
References
4- www.dragonbyte-tech.com/f4/vbactivity-vbshout-forumon-rpg-vbdownloads-vbquiz-updates-security-releases-6876/nvdPatchVendor Advisory
- www.securityfocus.com/bid/52713nvdThird Party AdvisoryVDB Entry
- exchange.xforce.ibmcloud.com/vulnerabilities/74347nvdThird Party AdvisoryVDB Entry
- secunia.com/advisories/48522nvdPermissions Required
News mentions
0No linked articles in our index yet.