Invision Power Board Index.PHP Act Parameter SQL Injection Vulnerability
BID:18782
CVE-2006-3544 |Info
Invision Power Board Index.PHP Act Parameter SQL Injection Vulnerability
| Bugtraq ID: | 18782 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-3544 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 03 2006 12:00AM |
| Updated: | Jan 07 2008 02:19PM |
| Credit: | Breeeeh is credited with the discovery of this vulnerability. |
| Vulnerable: |
Invision Power Services Invision Board 2.1.7 Invision Power Services Invision Board 1.3.1 Final Invision Power Services Invision Board 1.3 Final |
| Not Vulnerable: | |
Discussion
Invision Power Board Index.PHP Act Parameter SQL Injection Vulnerability
Invision Power Board is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Version 1.3 Final is affected; other versions may also be vulnerable to this issue.
Invision Power Board is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Version 1.3 Final is affected; other versions may also be vulnerable to this issue.
Exploit / POC
Invision Power Board Index.PHP Act Parameter SQL Injection Vulnerability
Attackers can exploit this issue through a web client.
The following proof-of-concept URI is available:
Attackers can exploit this issue through a web client.
The following proof-of-concept URI is available:
Solution / Fix
Invision Power Board Index.PHP Act Parameter SQL Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Invision Power Board Index.PHP Act Parameter SQL Injection Vulnerability
References:
References:
- Invision Board Homepage (Invision Power Services)
- INVISION POWER BOARD 2.1.7 ACTIVE XSS/SQL INJECTION EXPLOIT ([email protected])
- Invision Power Board v1.3 Final SQL Injection (Breeeeh)