Back

CVE-2005-0429

Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showforumusers is enabled, allows remote attackers to execute inject arbitrary PHP commands via the comma parameter.

Published: May 2, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (5)

Vendor Product Version
jelsoft vbulletin 3.0
jelsoft vbulletin 3.0.1
jelsoft vbulletin 3.0.2
jelsoft vbulletin 3.0.3
jelsoft vbulletin 3.0.4

GitHub Security Advisory GHSA-jcr9-hcrf-g3rg

Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 1.93%

Top 22% most likely to be exploited

Threat Score 20.6 / 100

Data Sources

NVD EPSS GitHub