CVE-2005-1070 – Invision Power Board 1.x - 'ST' SQL Injection
https://notcve.org/view.php?id=CVE-2005-1070
SQL injection vulnerability in index.php in Invision Power Board 1.3.1 Final and earlier allows remote attackers to execute arbitrary SQL commands via the st parameter. • https://www.exploit-db.com/exploits/25380 http://www.securityfocus.com/archive/1/395515 http://www.securityfocus.com/bid/13097 http://www.securitytracker.com/alerts/2005/Apr/1013676.html https://exchange.xforce.ibmcloud.com/vulnerabilities/20059 •
CVE-2005-0886 – Invision Power Board 1.x/2.0 - HTML Injection
https://notcve.org/view.php?id=CVE-2005-0886
Cross-site scripting (XSS) vulnerability in Invision Power Board 2.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an HTTP POST request. • https://www.exploit-db.com/exploits/25267 http://www.securityfocus.com/bid/12888 •
CVE-2005-0477 – Invision Power Board (IP.Board) 1.x/2.0.3 - SML Code Script Injection
https://notcve.org/view.php?id=CVE-2005-0477
Cross-site scripting (XSS) vulnerability in the SML code for Invision Power Board 1.3.1 FINAL allows remote attackers to inject arbitrary web script via (1) a signature file or (2) a message post containing an IMG tag within a COLOR tag whose style is set to background:url. Vulnerabilidad de secuencias de comandos en sitios cruzados en el código SML de Invision Power Board 1.3.1 FINAL permite a atacantes remotos la inyección de sripts arbitrarios mediante: un fichero de firmas, un mensaje que contiene una etiqueta IMG en una etiqueta COLOR cuyo estilo está puesto como background:url. • https://www.exploit-db.com/exploits/25143 http://marc.info/?l=bugtraq&m=110868196922995&w=2 https://exchange.xforce.ibmcloud.com/vulnerabilities/19399 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2004-1578
https://notcve.org/view.php?id=CVE-2004-1578
Cross-site scripting (XSS) vulnerability in index.php in Invision Power Board 2.0.0 allows remote attackers to execute arbitrary web script or HTML via the Referer field in the HTTP header. • http://marc.info/?l=bugtraq&m=109701091207517&w=2 http://secunia.com/advisories/12740 http://www.securityfocus.com/bid/11332 https://exchange.xforce.ibmcloud.com/vulnerabilities/17604 •
CVE-2004-1531 – Invision Power Board 2.0.0 < 2.0.2 - SQL Injection
https://notcve.org/view.php?id=CVE-2004-1531
SQL injection vulnerability in post.php in Invision Power Board (IPB) 2.0.0 through 2.0.2 allows remote attackers to execute arbitrary SQL commands via the qpid parameter. • https://www.exploit-db.com/exploits/648 http://forums.invisionpower.com/index.php?showtopic=154916 http://marc.info/?l=bugtraq&m=110079592702417&w=2 http://marc.info/?l=bugtraq&m=111454805209191&w=2 http://marc.info/?l=bugtraq&m=111462421824202&w=2 http://secunia.com/advisories/13245 http://www.securityfocus.com/bid/11703 https://exchange.xforce.ibmcloud.com/vulnerabilities/18164 •