Invision Power Board Index.PHP SQL Injection Vulnerability
BID:9232
Info
Invision Power Board Index.PHP SQL Injection Vulnerability
| Bugtraq ID: | 9232 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 16 2003 12:00AM |
| Updated: | Dec 16 2003 12:00AM |
| Credit: | Discovery is credited to JeiAr <[email protected]>. |
| Vulnerable: |
Invision Power Services Invision Board 2.0 Alpha 3 Invision Power Services Invision Board 1.3 Invision Power Services Invision Board 1.2 Invision Power Services Invision Board 1.1.2 Invision Power Services Invision Board 1.1.1 Invision Power Services Invision Board 1.0.1 Invision Power Services Invision Board 1.0 |
| Not Vulnerable: | |
Discussion
Invision Power Board Index.PHP SQL Injection Vulnerability
Invision Power Board is prone to SQL injection attacks. This issue will permit a remote attacker to manipulate database queries, possibly resulting in bulletin board compromise, information disclosure or other consequences.
Invision Power Board is prone to SQL injection attacks. This issue will permit a remote attacker to manipulate database queries, possibly resulting in bulletin board compromise, information disclosure or other consequences.
Exploit / POC
Invision Power Board Index.PHP SQL Injection Vulnerability
This issue may be exploited with a web browser.
This issue may be exploited with a web browser.
Solution / Fix
Invision Power Board Index.PHP SQL Injection Vulnerability
Solution:
The vendor has released IPB 1.3 Security Update 12-16 (1.3) to address this issue.
Invision Power Services Invision Board 1.3
Solution:
The vendor has released IPB 1.3 Security Update 12-16 (1.3) to address this issue.
Invision Power Services Invision Board 1.3
-
Invision Power Services IPB 1.3 Security Update 12-16 (1.3)
http://www.invisionboard.com/download/index.php?act=dl&s=1&id=12&p=1
References
Invision Power Board Index.PHP SQL Injection Vulnerability
References:
References:
- Invision Board Homepage (Invision Power Services)
- Security Update for 1.3 (Invision Power Services)
- Invision Power Board SQL Injection Vuln [ All Versions ] (JeiAr
)