CVE-2007-3326 describes multiple directory traversal vulnerabilities in vBulletin 3.x.x, allowing remote attackers to redirect users to arbitrary local files. Specifically, a ".." (dot dot) in the 'loc' parameter of admincp/index.php or the Hyperlink information URL field for post topics in showthread.php could lead to cross-site scripting (XSS) and other attacks. This vulnerability has a CVSS score of 5.8, indicating a medium severity due to its network-based attack vector, medium access complexity, and partial impact on integrity and availability. There is no evidence of active exploitation, no known exploit code in Metasploit or ExploitDB, and minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.0CPE matchmatch criteria | cpe:2.3:a:jelsoft:vbulletin:3.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.