Jelsoft vBulletin 3.5.4 allows remote attackers to register multiple arbitrary users and cause a denial of service (resource consumption) via a large number of requests to register.php. NOTE: the vendor has disputed this vulnerability, stating "If you have the CAPTCHA enabled then the registrations wont even go through. ... if you are talking about the flood being allowed in the first place then surely this is something that should be handled at the server level.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2006-08-21T21:00:00
Updated: 2024-08-07T19:06:06.898Z
Reserved: 2006-08-21T00:00:00
Link: CVE-2006-4272
Vulnrichment
No data.
NVD
Status : Modified
Published: 2006-08-21T21:04:00.000
Modified: 2024-11-21T00:15:32.780
Link: CVE-2006-4272
Redhat
No data.