Invision Power Board Index.PHP CK Parameter SQL Injection Vulnerability
BID:17690
Info
Invision Power Board Index.PHP CK Parameter SQL Injection Vulnerability
| Bugtraq ID: | 17690 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 25 2006 12:00AM |
| Updated: | Apr 27 2006 07:46PM |
| Credit: | IceShaman and Wells are credited with the discovery of this vulnerability. |
| Vulnerable: |
Invision Power Services Invision Power Board 2.1.5.2006.03.08 Invision Power Services Invision Board 2.1.5 Invision Power Services Invision Board 2.1 Alpha2 Invision Power Services Invision Board 2.1 Invision Power Services Invision Board 2.0.4 Invision Power Services Invision Board 2.0.3 Invision Power Services Invision Board 2.0.2 Invision Power Services Invision Board 2.0.1 Invision Power Services Invision Board 2.0 PF2 Invision Power Services Invision Board 2.0 PF1 Invision Power Services Invision Board 2.0 PDR3 Invision Power Services Invision Board 2.0 Alpha 3 Invision Power Services Invision Board 2.0 |
| Not Vulnerable: |
Invision Power Services Invision Power Board 2.1.5.2006.04.25 |
Discussion
Invision Power Board Index.PHP CK Parameter SQL Injection Vulnerability
Invision Power Board is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Invision Power Board is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Exploit / POC
Invision Power Board Index.PHP CK Parameter SQL Injection Vulnerability
This issue can be exploited through a web client.
The following proof-of-concept URI is available:
This issue can be exploited through a web client.
The following proof-of-concept URI is available:
Solution / Fix
Invision Power Board Index.PHP CK Parameter SQL Injection Vulnerability
Solution:
The vendor has released an update to address this and other versions.
Invision Power Services Invision Power Board 2.1.5.2006.03.08
Invision Power Services Invision Board 2.0 PF1
Invision Power Services Invision Board 2.0 PDR3
Invision Power Services Invision Board 2.0
Invision Power Services Invision Board 2.0 PF2
Invision Power Services Invision Board 2.0 Alpha 3
Invision Power Services Invision Board 2.0.1
Invision Power Services Invision Board 2.0.2
Invision Power Services Invision Board 2.0.3
Invision Power Services Invision Board 2.0.4
Invision Power Services Invision Board 2.1
Invision Power Services Invision Board 2.1 Alpha2
Invision Power Services Invision Board 2.1.5
Solution:
The vendor has released an update to address this and other versions.
Invision Power Services Invision Power Board 2.1.5.2006.03.08
-
Invision Power Services ipb215_su250406.zip
http://forums.invisionpower.com/index.php?s=fa2b4307b09f7a0f5daafdfb86 8b610d&act=Attach&type=post&id=9981
Invision Power Services Invision Board 2.0 PF1
-
Invision Power Services ipb200_su250406.zip
http://forums.invisionpower.com/index.php?s=fa2b4307b09f7a0f5daafdfb86 8b610d&act=Attach&type=post&id=9980
Invision Power Services Invision Board 2.0 PDR3
-
Invision Power Services ipb200_su250406.zip
http://forums.invisionpower.com/index.php?s=fa2b4307b09f7a0f5daafdfb86 8b610d&act=Attach&type=post&id=9980
Invision Power Services Invision Board 2.0
-
Invision Power Services ipb200_su250406.zip
http://forums.invisionpower.com/index.php?s=fa2b4307b09f7a0f5daafdfb86 8b610d&act=Attach&type=post&id=9980
Invision Power Services Invision Board 2.0 PF2
-
Invision Power Services ipb200_su250406.zip
http://forums.invisionpower.com/index.php?s=fa2b4307b09f7a0f5daafdfb86 8b610d&act=Attach&type=post&id=9980
Invision Power Services Invision Board 2.0 Alpha 3
-
Invision Power Services ipb200_su250406.zip
http://forums.invisionpower.com/index.php?s=fa2b4307b09f7a0f5daafdfb86 8b610d&act=Attach&type=post&id=9980
Invision Power Services Invision Board 2.0.1
-
Invision Power Services ipb200_su250406.zip
http://forums.invisionpower.com/index.php?s=fa2b4307b09f7a0f5daafdfb86 8b610d&act=Attach&type=post&id=9980
Invision Power Services Invision Board 2.0.2
-
Invision Power Services ipb200_su250406.zip
http://forums.invisionpower.com/index.php?s=fa2b4307b09f7a0f5daafdfb86 8b610d&act=Attach&type=post&id=9980
Invision Power Services Invision Board 2.0.3
-
Invision Power Services ipb200_su250406.zip
http://forums.invisionpower.com/index.php?s=fa2b4307b09f7a0f5daafdfb86 8b610d&act=Attach&type=post&id=9980
Invision Power Services Invision Board 2.0.4
-
Invision Power Services ipb200_su250406.zip
http://forums.invisionpower.com/index.php?s=fa2b4307b09f7a0f5daafdfb86 8b610d&act=Attach&type=post&id=9980
Invision Power Services Invision Board 2.1
-
Invision Power Services ipb215_su250406.zip
http://forums.invisionpower.com/index.php?s=fa2b4307b09f7a0f5daafdfb86 8b610d&act=Attach&type=post&id=9981
Invision Power Services Invision Board 2.1 Alpha2
-
Invision Power Services ipb215_su250406.zip
http://forums.invisionpower.com/index.php?s=fa2b4307b09f7a0f5daafdfb86 8b610d&act=Attach&type=post&id=9981
Invision Power Services Invision Board 2.1.5
-
Invision Power Services ipb215_su250406.zip
http://forums.invisionpower.com/index.php?s=fa2b4307b09f7a0f5daafdfb86 8b610d&act=Attach&type=post&id=9981
References
Invision Power Board Index.PHP CK Parameter SQL Injection Vulnerability
References:
References:
- Invision Gallery Product Page (Invision Power Services)
- Invision Power Services > Invision Power Services, Inc. > Company News and Updat (Invision Power Services)
- Invision Vulnerabilities, including remote code execution ([email protected])