Description
vBulletin 4 is vulnerable to an SQL injection vulnerability, which may allow an attacker can execute malicious SQL statements that control a web application's database server.
Remediation
Upgrade to the latest version of vBulletin.
References
vBulletin 4.0.x => 4.1.2 (search.php) SQL Injection Vulnerability
Related Vulnerabilities
WordPress Plugin Easy Contact Form Lite 'sort_row.request.php' SQL Injection (1.0.7)
WordPress 4.3.x Possible SQL Injection Vulnerability (4.3 - 4.3.12)
WordPress Plugin RSVPMaker SQL Injection (6.1.9)
WordPress Plugin WORDPRESS VIDEO GALLERY SQL Injection (2.7)
WordPress Plugin Membership by Supsystic SQL Injection (1.4.7)