Show filters
61 Total Results
Displaying 31-40 of 61
Sort by:
Attacker Value
Unknown

CVE-2007-2349

Disclosure Date: April 30, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Invision Power Board (IP.Board) 2.1.x and 2.2.x allows remote attackers to inject arbitrary web script or HTML by uploading crafted images or PDF files.
0
Attacker Value
Unknown

CVE-2006-7071

Disclosure Date: March 02, 2007 (last updated October 04, 2023)
SQL injection vulnerability in classes/class_session.php in Invision Power Board (IPB) 2.1 up to 2.1.6 allows remote attackers to execute arbitrary SQL commands via the CLIENT_IP parameter.
0
Attacker Value
Unknown

CVE-2006-7064

Disclosure Date: February 24, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in forum/admin.php for Invision Power Board (IPB) 2.1.6 and earlier allows remote attackers to inject arbitrary web script or HTML as the administrator via the phpinfo parameter.
0
Attacker Value
Unknown

CVE-2006-5204

Disclosure Date: October 10, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in action_admin/member.php in Invision Power Board (IPB) 2.1.7 and earlier allows remote authenticated users to inject arbitrary web script or HTML via a reference to a script in the avatar setting, which can be leveraged for a cross-site request forgery (CSRF) attack involving forced SQL execution by an admin.
0
Attacker Value
Unknown

CVE-2006-5203

Disclosure Date: October 10, 2006 (last updated October 04, 2023)
Invision Power Board (IPB) 2.1.7 and earlier allows remote restricted administrators to inject arbitrary web script or HTML, or execute arbitrary SQL commands, via a forum description that contains a crafted image with PHP code, which is executed when the user visits the "Manage Forums" link in the Admin control panel.
0
Attacker Value
Unknown

CVE-2006-4155

Disclosure Date: August 16, 2006 (last updated October 04, 2023)
Unspecified vulnerability in func_topic_threaded.php (aka threaded view mode) in Invision Power Board (IPB) before 2.1.7 21013.60810.s allows remote attackers to "access posts outside the topic."
0
Attacker Value
Unknown

CVE-2006-3543

Disclosure Date: July 13, 2006 (last updated November 08, 2023)
Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 1.x and 2.x allow remote attackers to execute arbitrary SQL commands via the (1) idcat and (2) code parameters in a ketqua action in index.php; the id parameter in a (3) Attach and (4) ref action in index.php; the CODE parameter in a (5) Profile, (6) Login, and (7) Help action in index.php; and the (8) member_id parameter in coins_list.php. NOTE: the developer has disputed this issue, stating that the "CODE attribute is never present in an SQL query" and the "'ketqua' [action] and file 'coin_list.php' are not standard IPB 2.x features". It is unknown whether these vectors are associated with an independent module or modification of IPB
0
Attacker Value
Unknown

CVE-2006-3197

Disclosure Date: June 23, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.1.6 and earlier allows remote attackers to inject arbitrary web script or HTML via a POST that contains hexadecimal-encoded HTML.
0
Attacker Value
Unknown

CVE-2006-2498

Disclosure Date: May 20, 2006 (last updated October 04, 2023)
Invision Power Board (IPB) before 2.1.6 allows remote attackers to execute arbitrary PHP script via attack vectors involving (1) the post_icon variable in classes/post/class_post.php and (2) the df value in action_public/moderate.php.
0
Attacker Value
Unknown

CVE-2006-2204

Disclosure Date: May 05, 2006 (last updated October 04, 2023)
SQL injection vulnerability in the topic deletion functionality (post_delete function in func_mod.php) for Invision Power Board 2.1.5 allows remote authenticated moderators to execute arbitrary SQL commands via the selectedpids parameter, which bypasses an integer value check when the $id variable is an array.
0