Back

CVE-2004-1515

SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote attackers to execute arbitrary SQL statements via the fsel parameter, as demonstrated using last.php.

Published: Dec 31, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (11)

Vendor Product Version
jelsoft vbulletin 3.0.0
jelsoft vbulletin 3.0.0_beta_2
jelsoft vbulletin 3.0.0_can4
jelsoft vbulletin 3.0.0_rc4
jelsoft vbulletin 3.0.1
jelsoft vbulletin 3.0.2
jelsoft vbulletin 3.0.3
jelsoft vbulletin 3.0.4
jelsoft vbulletin 3.0.5
jelsoft vbulletin 3.0.6
jelsoft vbulletin 3.0_beta_2

GitHub Security Advisory GHSA-rphm-9gg2-wrrv

SQL injection vulnerability in (1) ttlast.php and (2) last10.php in vBulletin 3.0.x allows remote...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.01%

Top 40% most likely to be exploited

Threat Score 30.3 / 100

Data Sources

NVD EPSS GitHub