Vulnerabilities > Invision Power Services > Critical

DATE CVE VULNERABILITY TITLE RISK
2007-02-24 CVE-2006-7064 Cross-Site Scripting vulnerability in Invision Power Board
Cross-site scripting (XSS) vulnerability in forum/admin.php for Invision Power Board (IPB) 2.1.6 and earlier allows remote attackers to inject arbitrary web script or HTML as the administrator via the phpinfo parameter.
network
invision-power-services
critical
9.3
2004-11-23 CVE-2004-0338 SQL Injection vulnerability in Invision Power Board Search.PHP st
SQL injection vulnerability in search.php for Invision Board Forum allows remote attackers to execute arbitrary SQL queries via the st parameter.
network
low complexity
invision-power-services
critical
10.0