Vulnerabilities > Invision Power Services > High

DATE CVE VULNERABILITY TITLE RISK
2006-08-16 CVE-2006-4155 Remote Security vulnerability in Invision Power Board
Unspecified vulnerability in func_topic_threaded.php (aka threaded view mode) in Invision Power Board (IPB) before 2.1.7 21013.60810.s allows remote attackers to "access posts outside the topic."
network
low complexity
invision-power-services
7.5
2006-05-05 CVE-2006-2217 SQL Injection vulnerability in Invision Power Board
SQL injection vulnerability in index.php in Invision Power Board allows remote attackers to execute arbitrary SQL commands via the pid parameter in a reputation action.
network
low complexity
invision-power-services
7.5
2006-04-29 CVE-2006-2097 SQL Injection vulnerability in Invision Power Board Func_msg.PHP
SQL injection vulnerability in func_msg.php in Invision Power Board (IPB) 2.1.4 allows remote attackers to execute arbitrary SQL commands via the from_contact field in a private message (PM).
network
low complexity
invision-power-services
7.5
2006-03-19 CVE-2006-1288 SQL-Injection vulnerability in Invision Power Services Invision Power Board 2.0.4/2.1.4
Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 2.0.4 and 2.1.4 before 20060105 allow remote attackers to execute arbitrary SQL commands via cookies, related to (1) arrays of id/stamp pairs and (2) the keys in arrays of key/value pairs in ipsclass.php; (3) the topics variable in usercp.php; and the topicsread cookie in (4) topics.php, (5) search.php, and (6) forums.php.
network
low complexity
invision-power-services
7.5
2006-03-09 CVE-2006-1076 SQL Injection vulnerability in Invision Power Services Invision Power Board 2.1.5
SQL injection vulnerability in index.php, possibly during a showtopic operation, in Invision Power Board (IPB) 2.1.5 allows remote attackers to execute arbitrary SQL commands via the st parameter.
network
low complexity
invision-power-services
7.5
2005-11-01 CVE-2005-3395 SQL Injection vulnerability in Invision Power Services Invision Gallery 2.0.3
SQL injection vulnerability in Invision Gallery 2.0.3 allows remote attackers to execute arbitrary SQL commands via the st parameter.
network
low complexity
invision-power-services
7.5
2005-06-09 CVE-2005-1948 SQL Injection vulnerability in Invision Power Services Invision Gallery 1.0.1/1.3
Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL commands via (1) the comment parameter in an editcomment action or (2) the rating parameter when voting on a photo.
network
low complexity
invision-power-services
7.5
2005-06-09 CVE-2005-1946 SQL-Injection vulnerability in Invision Community Blog 1.0/1.1
Multiple SQL injection vulnerabilities in Invision Blog before 1.1.2 Final allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to an editentry, replyentry, or editcomment action, or (2) the mid parameter to an aboutme action.
network
low complexity
invision-power-services
7.5
2005-05-16 CVE-2005-1598 SQL Injection vulnerability in Invision Power Board Login.PHP
SQL injection vulnerability in Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via a crafted cookie password hash (pass_hash) that modifies the internal $pid variable.
network
low complexity
invision-power-services
7.5
2005-05-02 CVE-2005-0217 SQL Injection vulnerability in Invision Power Services Invision Community Blog 1.0
SQL injection vulnerability in index.php in Invision Community Blog allows remote attackers to execute arbitrary SQL commands via the eid parameter.
network
low complexity
invision-power-services
7.5