[] NeoSense

vBulletin 1.0/2.x/3.0 - 'index.php' User Interface Spoofing

Author: p0rk
type: webapps
platform: php
port: 
date_added: 2004-05-17 
date_updated: 2013-01-15 
verified: 1 
codes: CVE-2004-2288;OSVDB-19023 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/10362/info

A weakness has been reported to exist in the VBulletin software that may allow an attacker to spoof parts of the VBulletin interface. The issue exists due to improper validation of user-supplied data.

Remote attackers may potentially exploit this issue, by convincing a VBulletin administrator to follow a specially crafted URI. The URI would contain a URI to a remote attacker owned HTML page as a value for the affected parameter of the 'index.php' script. If the administrator were to follow this link, part of the VBulletin user interface may be spoofed by the attacker.

http://forums.example.com/admincp/index.php?loc=http://www.example.com