Show filters
68 Total Results
Displaying 31-40 of 68
Sort by:
Attacker Value
Unknown

CVE-2014-4928

Disclosure Date: March 20, 2018 (last updated November 26, 2024)
SQL injection vulnerability in Invision Power Board (aka IPB or IP.Board) before 3.4.6 allows remote attackers to execute arbitrary SQL commands via the cId parameter.
0
Attacker Value
Unknown

CVE-2015-3313

Disclosure Date: September 07, 2017 (last updated November 26, 2024)
SQL injection vulnerability in WordPress Community Events plugin before 1.4.
0
Attacker Value
Unknown

CVE-2017-12939

Disclosure Date: August 18, 2017 (last updated November 26, 2024)
A Remote Code Execution vulnerability was identified in all Windows versions of Unity Editor, e.g., before 5.3.8p2, 5.4.x before 5.4.5p5, 5.5.x before 5.5.4p3, 5.6.x before 5.6.3p1, and 2017.x before 2017.1.0p4.
0
Attacker Value
Unknown

CVE-2017-9578

Disclosure Date: June 16, 2017 (last updated November 08, 2023)
The "RVCB Mobile" by RVCB Mobile Banking app 3.0.0 -- aka rvcb-mobile/id757928895 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2017-8899

Disclosure Date: May 11, 2017 (last updated November 26, 2024)
Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has a composite of Stored XSS and Information Disclosure issues in the attachments feature found in User CP. This can be triggered by any Invision Power Board user and can be used to gain access to moderator/admin accounts. The primary cause is the ability to upload an SVG document with a crafted attribute such an onload; however, full path disclosure is required for exploitation.
0
Attacker Value
Unknown

CVE-2017-8897

Disclosure Date: May 11, 2017 (last updated November 26, 2024)
Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has pre-auth reflected XSS in the IPS UTF8 Converter v1.1.18: admin/convertutf8/index.php?controller= is the attack vector. This UTF8 Converter vulnerability can easily be used to make a malicious announcement affecting any Invision Power Board user who views the announcement.
0
Attacker Value
Unknown

CVE-2017-8898

Disclosure Date: May 11, 2017 (last updated November 26, 2024)
Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has stored XSS in the Announcements, allowing privilege escalation from an Invision Power Board moderator to an admin. An attack uses the announce_content parameter in an index.php?/modcp/announcements/&action=create request. This is related to the "<> Source" option.
0
Attacker Value
Unknown

CVE-2016-2564

Disclosure Date: April 23, 2017 (last updated November 08, 2023)
Invision Power Services (IPS) Community Suite before 4.1.9 makes session hijack easier by relying on the PHP uniqid function without the more_entropy flag. Attackers can guess an Invision Power Board session cookie if they can predict the exact time of cookie generation.
0
Attacker Value
Unknown

CVE-2016-6174

Disclosure Date: July 12, 2016 (last updated November 25, 2024)
applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.1.13, when used with PHP before 5.4.24 or 5.5.x before 5.5.8, allows remote attackers to execute arbitrary code via the content_class parameter.
0
Attacker Value
Unknown

CVE-2015-6812

Disclosure Date: September 04, 2015 (last updated October 05, 2023)
Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.0.12.1 allows remote attackers to cause a denial of service (loop and memory consumption) via a crafted URL.
0