Show filters
26 Total Results
Displaying 11-20 of 26
Sort by:
Attacker Value
Unknown
CVE-2006-3197
Disclosure Date: June 23, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.1.6 and earlier allows remote attackers to inject arbitrary web script or HTML via a POST that contains hexadecimal-encoded HTML.
0
Attacker Value
Unknown
CVE-2006-2498
Disclosure Date: May 20, 2006 (last updated October 04, 2023)
Invision Power Board (IPB) before 2.1.6 allows remote attackers to execute arbitrary PHP script via attack vectors involving (1) the post_icon variable in classes/post/class_post.php and (2) the df value in action_public/moderate.php.
0
Attacker Value
Unknown
CVE-2006-2204
Disclosure Date: May 05, 2006 (last updated October 04, 2023)
SQL injection vulnerability in the topic deletion functionality (post_delete function in func_mod.php) for Invision Power Board 2.1.5 allows remote authenticated moderators to execute arbitrary SQL commands via the selectedpids parameter, which bypasses an integer value check when the $id variable is an array.
0
Attacker Value
Unknown
CVE-2006-2217
Disclosure Date: May 05, 2006 (last updated October 04, 2023)
SQL injection vulnerability in index.php in Invision Power Board allows remote attackers to execute arbitrary SQL commands via the pid parameter in a reputation action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2006-2097
Disclosure Date: April 29, 2006 (last updated October 04, 2023)
SQL injection vulnerability in func_msg.php in Invision Power Board (IPB) 2.1.4 allows remote attackers to execute arbitrary SQL commands via the from_contact field in a private message (PM).
0
Attacker Value
Unknown
CVE-2006-2059
Disclosure Date: April 26, 2006 (last updated October 04, 2023)
action_public/search.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary PHP code via a search with a crafted value of the lastdate parameter, which alters the behavior of a regular expression to add a "#e" (execute) modifier.
0
Attacker Value
Unknown
CVE-2006-2061
Disclosure Date: April 26, 2006 (last updated October 04, 2023)
SQL injection vulnerability in lib/func_taskmanager.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary SQL commands via the ck parameter, which can inject at most 32 characters.
0
Attacker Value
Unknown
CVE-2006-2060
Disclosure Date: April 26, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in action_admin/paysubscriptions.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote authenticated administrators to include and execute arbitrary local PHP files via a .. (dot dot) in the name parameter, preceded by enough backspace (%08) characters to erase the initial static portion of a filename.
0
Attacker Value
Unknown
CVE-2006-1369
Disclosure Date: March 23, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.1.5 and earlier before 20060308 allows remote attackers to inject arbitrary web script or HTML via a Private Message (PM) in certain circumstances.
0
Attacker Value
Unknown
CVE-2006-1287
Disclosure Date: March 19, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.0.4 and 2.1.4 before 20060130 allows remote attackers to steal cookies and probably conduct other activities when the victim is using Internet Explorer.
0