Vulnerabilities > Invision Power Services > Invision Power Board > 1.1.1

DATE CVE VULNERABILITY TITLE RISK
2009-03-31 CVE-2008-6565 Cross-Site Scripting vulnerability in Invision Power Services Invision Power Board
Cross-site scripting (XSS) vulnerability in Invision Power Board 2.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via an IFRAME tag in the signature.
4.3
2007-02-24 CVE-2006-7064 Cross-Site Scripting vulnerability in Invision Power Board
Cross-site scripting (XSS) vulnerability in forum/admin.php for Invision Power Board (IPB) 2.1.6 and earlier allows remote attackers to inject arbitrary web script or HTML as the administrator via the phpinfo parameter.
network
invision-power-services
critical
9.3
2006-10-10 CVE-2006-5204 Cross-Site Scripting vulnerability in Invision Power Board
Cross-site scripting (XSS) vulnerability in action_admin/member.php in Invision Power Board (IPB) 2.1.7 and earlier allows remote authenticated users to inject arbitrary web script or HTML via a reference to a script in the avatar setting, which can be leveraged for a cross-site request forgery (CSRF) attack involving forced SQL execution by an admin.
network
high complexity
invision-power-services
2.1
2006-10-10 CVE-2006-5203 Cross-Site Scripting vulnerability in Invision Power Board
Invision Power Board (IPB) 2.1.7 and earlier allows remote restricted administrators to inject arbitrary web script or HTML, or execute arbitrary SQL commands, via a forum description that contains a crafted image with PHP code, which is executed when the user visits the "Manage Forums" link in the Admin control panel.
network
high complexity
invision-power-services
5.1
2006-04-29 CVE-2006-2097 SQL Injection vulnerability in Invision Power Board Func_msg.PHP
SQL injection vulnerability in func_msg.php in Invision Power Board (IPB) 2.1.4 allows remote attackers to execute arbitrary SQL commands via the from_contact field in a private message (PM).
network
low complexity
invision-power-services
7.5
2005-03-30 CVE-2005-0477 Cross-Site Scripting vulnerability in Invision Power Services Invision Power Board
Cross-site scripting (XSS) vulnerability in the SML code for Invision Power Board 1.3.1 FINAL allows remote attackers to inject arbitrary web script via (1) a signature file or (2) a message post containing an IMG tag within a COLOR tag whose style is set to background:url.
4.3
2003-12-31 CVE-2003-1385 Code Injection vulnerability in Invision Power Services Invision Power Board 1.1.1
ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root_path parameter to reference a URL on a remote web server that contains the code.
6.8