4.1.5|vBulletin 4.1.5 attachment SQL Injection vulnerable \nPOC : $target/newattachment.php?do=assetmanager&values[f]=-1599+or(1,2)=(select*from(select+name_const(version(),1),name_const(version(),1) ​ )a)&contenttypeid=18&poststarttime=1360663633&posthash=4f5c850593e10c5450d9e880d58a56d8&insertinline=1
2.0.3|VBulletin 2.0.3 Calendar.php Command execution vulnerable \nPOC : $target/calendar.php?calbirthdays=1&action=getday&day=2001-8-15&comma=%22;echo%20'';%20echo%20%60<command>%20%60;die();echo%22\nEDB : https://www.exploit-db.com/exploits/21874/
2.0|VBulletin 2.0/2.2.x - XSS vulnerable \nPOC : $target/usercp.php?s=[Session ID]\"><Script>alert(document.cookie);</Script>\nEDB : https://www.exploit-db.com/exploits/21946/|VBulletin 2.0/2.2.x - XSS vulnerable \nPOC : $target/private.php?&action=newmessage&userid=[UID]&forward=[XSS]\nEDB : https://www.exploit-db.com/exploits/23865/|Other XSS Exploits \n EDB : https://www.exploit-db.com/exploits/22030/ \n EDB : https://www.exploit-db.com/exploits/22042/
2.2|VBulletin 2.0/2.2.x - XSS vulnerable \nPOC : $target/usercp.php?s=[Session ID]\"><Script>alert(document.cookie);</Script>\nEDB : https://www.exploit-db.com/exploits/21946/|VBulletin 2.0/2.2.x - XSS vulnerable \nPOC : $target/private.php?&action=newmessage&userid=[UID]&forward=[XSS]\nEDB : https://www.exploit-db.com/exploits/23865/|Other XSS Exploits \n EDB : https://www.exploit-db.com/exploits/22030/ \n EDB : https://www.exploit-db.com/exploits/22042/
3.0.1|VBulletin 3.0.1 newreply.php WYSIWYG_HTML parameter XSS\nEDB : https://www.exploit-db.com/exploits/24234/
3.0.4|vBulletin <= 3.0.4 - \"forumdisplay.php\" Code execution\nEDB : https://www.exploit-db.com/exploits/818/\nEDB : https://www.exploit-db.com/exploits/820/
3.0|vBulletin 3.0 Register.PHP HTML Injection vulnerability\nEDB : https://www.exploit-db.com/exploits/22990/|VBulletin 3.0 - Search.PHP XSS vulnerability\nEDB : https://www.exploit-db.com/exploits/23691/|VBulletin 3.0 ShowThread.PHP XSS vulnerability\nEDB : https://www.exploit-db.com/exploits/23823/|VBulletin 3.0 ForumDisplay.PHP XSS vulnerability\nEDB : https://www.exploit-db.com/exploits/23822/|VBulletin 3.0 vBulletin 3.0 - Private Message HTML Injection vulnerability\nEDB : https://www.exploit-db.com/exploits/22599/
1.0.1|VBulletin 1.0.1 lite/2.x/3.0 /admincp/template.php Multiple parameter XSS\nEDB : https://www.exploit-db.com/exploits/26283/| VBulletin 1.0.1 lite/2.x/3.0 /admincp/modlog.php orderby parameter XSS\nEDB : https://www.exploit-db.com/exploits/26282/|VBulletin 1.0.1 lite/2.x/3.0 /admincp/language.php goto parameter XSS\nEDB : https://www.exploit-db.com/exploits/26280/|VBulletin 1.0.1 lite/2.x/3.0 /admincp/index.php Multiple parameter XSS\nEDB : https://www.exploit-db.com/exploits/26279/|VBulletin 1.0.1 lite/2.x/3.0 /admincp/css.php group parameter XSS\nEDB : https://www.exploit-db.com/exploits/26278/|VBulletin 1.0.1 lite/2.x/3.0 /admincp/usertools.php ids parameter SQL Injection\nEDB : https://www.exploit-db.com/exploits/26276/|VBulletin 1.0.1 lite/2.x/3.0 /admincp/usertitle.php usertitleid parameter SQL Injection\nEDB : https://www.exploit-db.com/exploits/26274/|VBulletin 1.0.1 lite/2.x/3.0 joinrequests.php request parameter SQL Injection\nEDB : https://www.exploit-db.com/exploits/26273/
3.0.6|vBulletin <= 3.0.6 php Code Injection\nEDB : https://www.exploit-db.com/exploits/832/|vBulletin <= 3.0.6 (Template) Command execution Exploit (metasploit)\nEDB : https://www.exploit-db.com/exploits/1133/
3.5.2|VBulletin 3.5.2 Event Title HTML Injection vulnerability\nEDB : https://www.exploit-db.com/exploits/27019/
3.5.1|vBulletin 3.5.1 Vbugs.PHP XSS vulnerability\nEDB : https://www.exploit-db.com/exploits/27580/
3.0.8|vBulletin <= 3.0.8 accessible database backup searcher (update 3)\nEDB : https://www.exploit-db.com/exploits/1189/
3.0.1|vBulletin 3.0.10 Portal.PHP SQL Injection vulnerability\nEDB : https://www.exploit-db.com/exploits/27929/
4.1.5|XSS vulnerable \nPOC : $target/admincp/plugin.php\"><script>alert('XSS')</script>
4.1.4|XSS vulnerable \nPOC : $target/admincp/plugin.php\"><script>alert('XSS')</script>
4.1.3|XSS vulnerable \nPOC : $target/admincp/plugin.php\"><script>alert('XSS')</script>
3.0.9|Vbulletin 3.0.9/3.5.x Member.PHP XSS vulnerability\nEDB : https://www.exploit-db.com/exploits/28076/
3.5|Vbulletin 3.0.9/3.5.x Member.PHP XSS vulnerability\nEDB : https://www.exploit-db.com/exploits/28076/
3.0.14|VBulletin 3.0.14 global.php Encoded URL XSS\nEDB : https://www.exploit-db.com/exploits/28342/
2.3|VBulletin 2.3.x Global.PHP SQL Injection vulnerability\nEDB : https://www.exploit-db.com/exploits/28694/
3.6|VBulletin 3.6.x Admin Control Panel Index.PHP Multiple XSS vulnerabilities\nEDB : https://www.exploit-db.com/exploits/29079/
3.5|VBulletin 3.5.x/3.6.x SWF Script Injection vulnerability\nEDB : https://www.exploit-db.com/exploits/29338/
3.6|VBulletin 3.5.x/3.6.x SWF Script Injection vulnerability\nEDB : https://www.exploit-db.com/exploits/29338/
3.6.4|vBulletin <= 3.6.4 (inlinemod.php postids) Remote SQL Injection Exploit\nEDB : https://www.exploit-db.com/exploits/3387/
3.6.6|VBulletin <= 3.6.6 Calendar.PHP HTML Injection vulnerability\nEDB : https://www.exploit-db.com/exploits/30047/
3.6.10|vBulletin 3.6.10/3.7.1 - 'redirect' parameter XSS vulnerability\nEDB : https://www.exploit-db.com/exploits/31910/
3.7.1|vBulletin 3.6.10/3.7.1 - 'redirect' parameter XSS vulnerability\nEDB : https://www.exploit-db.com/exploits/31910/|vBulletin <= 3.7.1 Moderation Control Panel 'redirect' parameter XSS vulnerability\nEDB : https://www.exploit-db.com/exploits/31939/
3.6.10|vBulletin 3.6.10/3.7.2 - 'newpm[title]' parameter XSS vulnerability\nEDB : https://www.exploit-db.com/exploits/32285/
3.7.2|vBulletin 3.6.10/3.7.2 - 'newpm[title]' parameter XSS vulnerability\nEDB : https://www.exploit-db.com/exploits/32285/
3.7.3|vBulletin 3.7.3 - Visitor Message CSRF + Worm Exploit\nEDB : https://www.exploit-db.com/exploits/7174/
4.0.1|vBulletin 4.0.1 - 'misc.php' SQL Injection vulnerability\nEDB : https://www.exploit-db.com/exploits/33547/
3.5.4|vBulletin <= 3.5.4 - Multiple XSS vulnerabilities\nEDB : https://www.exploit-db.com/exploits/33624/
2.3|vBulletin 2.3.x - SQL Injection vulnerability\nEDB : https://www.exploit-db.com/exploits/11396/
3.0.0|vBulletin 3.0.0 - XSS vulnerability\nEDB : https://www.exploit-db.com/exploits/11395/
3.5.2|vBulletin 3.5.2 - XSS vulnerabilities\nEDB : https://www.exploit-db.com/exploits/11394/
4.0.2|vBulletin 4.0.2 - Multiple XSS vulnerabilities\nEDB : https://www.exploit-db.com/exploits/33660/|vBulletin 4.0.2 - Search XSS vulnerability\nEDB : https://www.exploit-db.com/exploits/33784/|vBulletin Blog 4.0.2 Title XSS vulnerability\nEDB : https://www.exploit-db.com/exploits/11871/
4.0.8|vBulletin 4.0.8 - Persistent XSS via Profile Customization\nEDB : https://www.exploit-db.com/exploits/15550/|vBulletin 4.0.8 PL1 - XSS Filter Bypass within profile customization\nEDB : https://www.exploit-db.com/exploits/15590/
3.8.4|vBulletin 3.8.4 & 3.8.5 Registration bypass vulnerability\nEDB : https://www.exploit-db.com/exploits/14833/
3.8.5|vBulletin 3.8.4 & 3.8.5 Registration bypass vulnerability\nEDB : https://www.exploit-db.com/exploits/14833/
4.0.8|vBulletin 4.0.8 - Persistent XSS via profile customization\nEDB : https://www.exploit-db.com/exploits/15550/
4.0.1|vBulletin 4.0.x <= 4.1.2 - (search.php) SQL Injection vulnerability\nEDB : https://www.exploit-db.com/exploits/17314/|vBulletin 4.0.x - 4.1.2 (search.php cat param) - SQL Injection Exploit\nEDB : https://www.exploit-db.com/exploits/34526/\nhttps://packetstormsecurity.com/files/128139/vBulletin-4.1.2-SQL-Injection.html
4.0.2|vBulletin 4.0.x <= 4.1.2 - (search.php) SQL Injection vulnerability\nEDB : https://www.exploit-db.com/exploits/17314/|vBulletin 4.0.x - 4.1.2 (search.php cat param) - SQL Injection Exploit\nEDB : https://www.exploit-db.com/exploits/34526/\nhttps://packetstormsecurity.com/files/128139/vBulletin-4.1.2-SQL-Injection.html
4.0.1|Vbulletin 4.0.x <= 4.1.3 - (messagegroupid) SQL Injection vulnerability (0day)\nEDB : https://www.exploit-db.com/exploits/17555/
4.0.2|Vbulletin 4.0.x <= 4.1.3 - (messagegroupid) SQL Injection vulnerability (0day)\nEDB : https://www.exploit-db.com/exploits/17555/
4.0.3|Vbulletin 4.0.x <= 4.1.3 - (messagegroupid) SQL Injection vulnerability (0day)\nEDB : https://www.exploit-db.com/exploits/17555/
4.1.7|vBulletin 4.1.7 Multiple Remote File Include vulnerabilities\nEDB : https://www.exploit-db.com/exploits/36273/
4.1.10|VBulletin 4.1.10 'announcementid' parameter SQL Injection vulnerability\nEDB : https://www.exploit-db.com/exploits/37062/
4.0.2|vBulletin Yet Another Awards System 4.0.2 - SQL Injection\nEDB : https://www.exploit-db.com/exploits/20956/
5.0.0|vBulletin 5.0.0 Beta 11 - 5.0.0 Beta 28 - SQL Injection\nEDB : https://www.exploit-db.com/exploits/24882/|vBulletin 5 - index.php/ajax/api/reputation/vote nodeid parameter SQL Injection\nEDB : https://www.exploit-db.com/exploits/30212/
5.1.0|vBulletin 5.1.X - Persistent XSS\nEDB : https://www.exploit-db.com/exploits/34579/
5.1.1|vBulletin 5.1.X - Persistent XSS\nEDB : https://www.exploit-db.com/exploits/34579/
5.1.2|vBulletin 5.1.X - Persistent XSS\nEDB : https://www.exploit-db.com/exploits/34579/
5.1.3|vBulletin 5.1.X - Persistent XSS\nEDB : https://www.exploit-db.com/exploits/34579/
5.1.4|vBulletin 5.1.X - Persistent XSS\nEDB : https://www.exploit-db.com/exploits/34579/
5.1.5|vBulletin 5.1.X - Persistent XSS\nEDB : https://www.exploit-db.com/exploits/34579/
5.1.2|vBulletin 5.1.2 SQL Injection Exploit\nhttps://rstforums.com/forum/87172-rst-vbulletin-5-1-2-sql-injection-exploit.rst
