← Back

CVE-2014-5102

nvd nist
Published: Jul 25, 2014Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

SQL injection vulnerability in vBulletin 5.0.4 through 5.1.3 Alpha 5 allows remote attackers to execute arbitrary SQL commands via the criteria[startswith] parameter to ajax/render/memberlist_items.

Affected (10)

Products: Vbulletin: Vbulletin
1 product
Vbulletin
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Vbulletin
Version 5.0.4
Version 5.0.5
Version 5.1.0
Version 5.1.0 rc1
Version 5.1.1
Version 5.1.2
Version 5.1.2 beta1
Version 5.1.2 rc1
Version 5.1.2 rc2
Version 5.1.3 alpha5

Timeline

No history available yet.