Vulnerabilities > CVE-2006-2217 - SQL Injection vulnerability in Invision Power Board

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
invision-power-services
exploit available

Summary

SQL injection vulnerability in index.php in Invision Power Board allows remote attackers to execute arbitrary SQL commands via the pid parameter in a reputation action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Exploit-Db

descriptionInvision Power Board 2.0/2.1 Index.PHP SQL Injection Vulnerability. CVE-2006-2217. Webapps exploit for php platform
idEDB-ID:27818
last seen2016-02-03
modified2006-05-04
published2006-05-04
reporteralmaster
sourcehttps://www.exploit-db.com/download/27818/
titleInvision Power Board 2.0/2.1 Index.PHP SQL Injection Vulnerability