Invision Power Board Privilege Escalation Vulnerability
BID:13797
Info
Invision Power Board Privilege Escalation Vulnerability
| Bugtraq ID: | 13797 |
| Class: | Design Error |
| CVE: |
CVE-2005-1816 |
| Remote: | Yes |
| Local: | No |
| Published: | May 28 2005 12:00AM |
| Updated: | Jul 12 2009 02:56PM |
| Credit: | Discovery is credited to Rapigator <[email protected]>. |
| Vulnerable: |
Invision Power Services Invision Board 2.0.4 Invision Power Services Invision Board 2.0.3 Invision Power Services Invision Board 2.0.2 Invision Power Services Invision Board 2.0.1 Invision Power Services Invision Board 2.0 PF2 Invision Power Services Invision Board 2.0 PF1 Invision Power Services Invision Board 2.0 PDR3 Invision Power Services Invision Board 2.0 Alpha 3 Invision Power Services Invision Board 2.0 Invision Power Services Invision Board 1.3.1 Final Invision Power Services Invision Board 1.3 Final Invision Power Services Invision Board 1.3 Invision Power Services Invision Board 1.3 Invision Power Services Invision Board 1.2 Invision Power Services Invision Board 1.1.2 Invision Power Services Invision Board 1.1.1 Invision Power Services Invision Board 1.0.1 Invision Power Services Invision Board 1.0 |
| Not Vulnerable: | |
Discussion
Invision Power Board Privilege Escalation Vulnerability
Invision Power Board is affected by a privilege escalation vulnerability. This issue can allow an authenticated attacker to gain elevated privileges.
Specifically, non-root administrator can become part of the root administrator group without providing sufficient authentication credentials.
This can allow a non-root administrator to gain root administrator privileges including complete access to the application and the underlying database.
Invision Power Board versions 1.0 to 2.0.4 are affected by this issue.
Invision Power Board is affected by a privilege escalation vulnerability. This issue can allow an authenticated attacker to gain elevated privileges.
Specifically, non-root administrator can become part of the root administrator group without providing sufficient authentication credentials.
This can allow a non-root administrator to gain root administrator privileges including complete access to the application and the underlying database.
Invision Power Board versions 1.0 to 2.0.4 are affected by this issue.
Exploit / POC
Invision Power Board Privilege Escalation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Invision Power Board Privilege Escalation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Invision Power Board Privilege Escalation Vulnerability
References:
References:
- Invision Board Homepage (Invision Power Services)