CVE-2006-4272 (CNNVD-200608-336)
中文标题:
Jelsoft vBulletin 'register.php'拒绝服务攻击漏洞
英文标题:
Jelsoft vBulletin 3.5.4 allows remote attackers to register multiple arbitrary users and cause a den...
漏洞描述
中文描述:
**有争议** Jelsoft vBulletin 3.5.4中,远程攻击者可借助对register.php脚本的大量请求来注册多个任意用户,并触发拒绝服务攻击(资源消耗型)。注:厂商对此漏洞存在争议,声称"如果启用了CAPTCHA,注册就不会通过......... 如果你们谈论的是存在泛洪攻击,那么这理应是服务器级要解决的问题。"
英文描述:
Jelsoft vBulletin 3.5.4 allows remote attackers to register multiple arbitrary users and cause a denial of service (resource consumption) via a large number of requests to register.php. NOTE: the vendor has disputed this vulnerability, stating "If you have the CAPTCHA enabled then the registrations wont even go through. ... if you are talking about the flood being allowed in the first place then surely this is something that should be handled at the server level.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| jelsoft | vbulletin | 3.5.4 | - | - |
cpe:2.3:a:jelsoft:vbulletin:3.5.4:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
AV:N/AC:L/Au:N/C:P/I:P/A:P
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2006-4272 |
2025-11-11 15:17:44 | 2025-11-11 07:32:36 |
| NVD | nvd_CVE-2006-4272 |
2025-11-11 14:51:50 | 2025-11-11 07:41:22 |
| CNNVD | cnnvd_CNNVD-200608-336 |
2025-11-11 15:08:52 | 2025-11-11 07:49:09 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 授权问题
- cnnvd_id: 未提取 -> CNNVD-200608-336
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.HIGH
- cvss_score: 未提取 -> 7.5
- cvss_vector: NOT_EXTRACTED -> AV:N/AC:L/Au:N/C:P/I:P/A:P
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 1
- data_sources: ['cve'] -> ['cve', 'nvd']