member2.php in vBulletin 2.2.9 and earlier does not properly restrict the $perpage variable to be an integer, which causes an error message to be reflected back to the user without quoting, which facilitates cross-site scripting (XSS) and possibly other attacks.
                
            References
                    Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    No history.
Information
                Published : 2002-12-31 05:00
Updated : 2008-09-05 20:32
NVD link : CVE-2002-2235
Mitre link : CVE-2002-2235
CVE.ORG link : CVE-2002-2235
JSON object : View
Products Affected
                jelsoft
- vbulletin
 
CWE
                
                    
                        
                        CWE-189
                        
            Numeric Errors
