index.php in Jelsoft vBulletin does not properly initialize a PHP variable that is used to store template information, which allows remote attackers to execute arbitrary PHP code via special characters in the templatecache parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vbulletin | Jelsoft | * | 1.1.5 (including) |
Vbulletin | Jelsoft | * | 2.0_beta_2 (including) |