TITLE:
vBulletin "Add Reminder" Script Insertion Vulnerability
SECUNIA ADVISORY ID:
SA18299
VERIFY ADVISORY:
http://secunia.com/advisories/18299/
CRITICAL:
Moderately critical
IMPACT:
Cross Site Scripting
WHERE:
From remote
SOFTWARE:
vBulletin 3.x
http://secunia.com/product/3212/
DESCRIPTION:
trueend5 has reported a vulnerability in vBulletin, which can be
exploited by malicious people to conduct script insertion attacks.
Input passed to the "title" field in "calendar.php" when adding a
"Single, All Day", "Ranged", or "Recurring" event isn't properly
sanitised before being used. This can be exploited to inject
arbitrary HTML and script code, which will be executed in a user's
browser session in context of an affected site when the malicious
user data is viewed via the "Add Reminder" functionality (i.e. when
visiting "calendar.php?do=addreminder&e=[eventid]").
The vulnerability has been reported in version 3.5.2. Other versions
may also be affected.
SOLUTION:
Edit the source code to ensure that input is properly sanitised.
PROVIDED AND/OR DISCOVERED BY:
trueend5, Security Science Researchers Institute Of Iran
ORIGINAL ADVISORY:
http://kapda.ir/advisory-177.html

Chowhound
Comic Vine
GameFAQs
GameSpot
Giant Bomb
TechRepublic