Vulnerabilities > Invision Power Services > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2006-08-16 | CVE-2006-4155 | Remote Security vulnerability in Invision Power Board Unspecified vulnerability in func_topic_threaded.php (aka threaded view mode) in Invision Power Board (IPB) before 2.1.7 21013.60810.s allows remote attackers to "access posts outside the topic." | 7.5 |
2006-05-05 | CVE-2006-2217 | SQL Injection vulnerability in Invision Power Board SQL injection vulnerability in index.php in Invision Power Board allows remote attackers to execute arbitrary SQL commands via the pid parameter in a reputation action. | 7.5 |
2006-04-29 | CVE-2006-2097 | SQL Injection vulnerability in Invision Power Board Func_msg.PHP SQL injection vulnerability in func_msg.php in Invision Power Board (IPB) 2.1.4 allows remote attackers to execute arbitrary SQL commands via the from_contact field in a private message (PM). | 7.5 |
2006-03-19 | CVE-2006-1288 | SQL-Injection vulnerability in Invision Power Services Invision Power Board 2.0.4/2.1.4 Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 2.0.4 and 2.1.4 before 20060105 allow remote attackers to execute arbitrary SQL commands via cookies, related to (1) arrays of id/stamp pairs and (2) the keys in arrays of key/value pairs in ipsclass.php; (3) the topics variable in usercp.php; and the topicsread cookie in (4) topics.php, (5) search.php, and (6) forums.php. | 7.5 |
2006-03-09 | CVE-2006-1076 | SQL Injection vulnerability in Invision Power Services Invision Power Board 2.1.5 SQL injection vulnerability in index.php, possibly during a showtopic operation, in Invision Power Board (IPB) 2.1.5 allows remote attackers to execute arbitrary SQL commands via the st parameter. | 7.5 |
2005-11-01 | CVE-2005-3395 | SQL Injection vulnerability in Invision Power Services Invision Gallery 2.0.3 SQL injection vulnerability in Invision Gallery 2.0.3 allows remote attackers to execute arbitrary SQL commands via the st parameter. | 7.5 |
2005-06-09 | CVE-2005-1948 | SQL Injection vulnerability in Invision Power Services Invision Gallery 1.0.1/1.3 Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL commands via (1) the comment parameter in an editcomment action or (2) the rating parameter when voting on a photo. | 7.5 |
2005-06-09 | CVE-2005-1946 | SQL-Injection vulnerability in Invision Community Blog 1.0/1.1 Multiple SQL injection vulnerabilities in Invision Blog before 1.1.2 Final allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to an editentry, replyentry, or editcomment action, or (2) the mid parameter to an aboutme action. | 7.5 |
2005-05-16 | CVE-2005-1598 | SQL Injection vulnerability in Invision Power Board Login.PHP SQL injection vulnerability in Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via a crafted cookie password hash (pass_hash) that modifies the internal $pid variable. | 7.5 |
2005-05-02 | CVE-2005-0217 | SQL Injection vulnerability in Invision Power Services Invision Community Blog 1.0 SQL injection vulnerability in index.php in Invision Community Blog allows remote attackers to execute arbitrary SQL commands via the eid parameter. | 7.5 |