Vulnerabilities > Invision Power Services > Invision Power Board > High

DATE CVE VULNERABILITY TITLE RISK
2010-03-02 CVE-2010-0802 SQL Injection vulnerability in Aleinbeen (Nv2) Awards 1.1.0
SQL injection vulnerability in index.php in (nv2) Awards 1.1.0, a modification for Invision Power Board, allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action.
network
low complexity
aleinbeen invision-power-services CWE-89
7.5
2008-09-22 CVE-2008-4171 SQL Injection vulnerability in Invision Power Services Invision Power Board 2.2/2.3
SQL injection vulnerability in xmlout.php in Invision Power Board (IP.Board or IPB) 2.2.x and 2.3.x allows remote attackers to execute arbitrary SQL commands via the name parameter.
network
low complexity
invision-power-services CWE-89
7.5
2007-10-29 CVE-2007-5688 SQL Injection vulnerability in multiple products
Multiple SQL injection vulnerabilities in directory.php in the Multi-Forums (aka Multi Host Forum Pro) module 1.3.3, for phpBB and Invision Power Board (IPB or IP.Board), allow remote attackers to execute arbitrary SQL commands via the (1) go and (2) cat parameters.
7.5
2007-09-17 CVE-2007-4913 Code Injection vulnerability in Invision Power Services Invision Power Board
ips_kernel/class_upload.php in Invision Power Board (IPB or IP.Board) 2.3.1 up to 20070912 allows remote attackers to upload arbitrary script files with crafted image filenames to uploads/, where they are saved with a .txt extension and are not executable.
network
low complexity
invision-power-services CWE-94
7.5
2007-06-14 CVE-2007-3219 Unspecified vulnerability in Invision Power Services Invision Power Board 2.2/2.2.1/2.2.2
Unspecified vulnerability in sources/action_public/xmlout.php in Invision Power Board (IPB or IP.Board) 2.2.0 through 2.2.2 allows remote attackers to modify another user's profile data, such as an AIM screen name or Yahoo! identity.
network
low complexity
invision-power-services
7.8
2007-03-02 CVE-2006-7071 SQL-Injection vulnerability in Invision Power Board
SQL injection vulnerability in classes/class_session.php in Invision Power Board (IPB) 2.1 up to 2.1.6 allows remote attackers to execute arbitrary SQL commands via the CLIENT_IP parameter.
network
low complexity
invision-power-services
7.5
2006-08-16 CVE-2006-4155 Remote Security vulnerability in Invision Power Board
Unspecified vulnerability in func_topic_threaded.php (aka threaded view mode) in Invision Power Board (IPB) before 2.1.7 21013.60810.s allows remote attackers to "access posts outside the topic."
network
low complexity
invision-power-services
7.5
2006-05-05 CVE-2006-2217 SQL Injection vulnerability in Invision Power Board
SQL injection vulnerability in index.php in Invision Power Board allows remote attackers to execute arbitrary SQL commands via the pid parameter in a reputation action.
network
low complexity
invision-power-services
7.5
2006-04-29 CVE-2006-2097 SQL Injection vulnerability in Invision Power Board Func_msg.PHP
SQL injection vulnerability in func_msg.php in Invision Power Board (IPB) 2.1.4 allows remote attackers to execute arbitrary SQL commands via the from_contact field in a private message (PM).
network
low complexity
invision-power-services
7.5
2006-03-19 CVE-2006-1288 SQL-Injection vulnerability in Invision Power Services Invision Power Board 2.0.4/2.1.4
Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 2.0.4 and 2.1.4 before 20060105 allow remote attackers to execute arbitrary SQL commands via cookies, related to (1) arrays of id/stamp pairs and (2) the keys in arrays of key/value pairs in ipsclass.php; (3) the topics variable in usercp.php; and the topicsread cookie in (4) topics.php, (5) search.php, and (6) forums.php.
network
low complexity
invision-power-services
7.5