Invision Power Board Profile.PHP Input Validation Vulnerability
BID:16518
Info
Invision Power Board Profile.PHP Input Validation Vulnerability
| Bugtraq ID: | 16518 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 06 2006 12:00AM |
| Updated: | Mar 08 2007 02:45AM |
| Credit: | [email protected] is credited with the discovery of this vulnerability. |
| Vulnerable: |
VBulletin VBulletin 3.5.3 VBulletin VBulletin 3.5.2 VBulletin VBulletin 3.5.1 VBulletin VBulletin 3.0.9 VBulletin VBulletin 3.0.8 VBulletin VBulletin 3.0.7 |
| Not Vulnerable: | |
Discussion
Invision Power Board Profile.PHP Input Validation Vulnerability
Invision Power Board is prone to an unspecified input-validation vulnerability.
Very little is known about this vulnerability; this BID will be updated when more details become available.
Versions 2.0.0 through 2.1.4 are vulnerable; other versions may also be affected.
Conflicting reports indicate that this issue may not be exploitable.
The vendor refutes that this issue is not exploitable after performing further analysis on the vulnerable application.
Invision Power Board is prone to an unspecified input-validation vulnerability.
Very little is known about this vulnerability; this BID will be updated when more details become available.
Versions 2.0.0 through 2.1.4 are vulnerable; other versions may also be affected.
Conflicting reports indicate that this issue may not be exploitable.
The vendor refutes that this issue is not exploitable after performing further analysis on the vulnerable application.
Exploit / POC
Invision Power Board Profile.PHP Input Validation Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Invision Power Board Profile.PHP Input Validation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
Invision Power Board Profile.PHP Input Validation Vulnerability
References:
References:
- Invision Board Homepage (Invision Power Services)
- Vulnerabilities in vBulltin(3.0.7 - 3.5.3) and IPB(2.0.0 - 2.1.4). ([email protected])