Page 2 of 17 results (0.001 seconds)

CVSS: 9.8EPSS: 0%CPEs: 8EXPL: 1

11 Apr 2005 — SQL injection vulnerability in index.php in Invision Power Board 1.3.1 Final and earlier allows remote attackers to execute arbitrary SQL commands via the st parameter. • https://www.exploit-db.com/exploits/25380 •

CVSS: 6.1EPSS: 0%CPEs: 15EXPL: 1

26 Mar 2005 — Cross-site scripting (XSS) vulnerability in Invision Power Board 2.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an HTTP POST request. • https://www.exploit-db.com/exploits/25267 •

CVSS: 6.1EPSS: 0%CPEs: 8EXPL: 1

19 Feb 2005 — Cross-site scripting (XSS) vulnerability in the SML code for Invision Power Board 1.3.1 FINAL allows remote attackers to inject arbitrary web script via (1) a signature file or (2) a message post containing an IMG tag within a COLOR tag whose style is set to background:url. Vulnerabilidad de secuencias de comandos en sitios cruzados en el código SML de Invision Power Board 1.3.1 FINAL permite a atacantes remotos la inyección de sripts arbitrarios mediante: un fichero de firmas, un mensaje que contiene una e... • https://www.exploit-db.com/exploits/25143 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 10.0EPSS: 0%CPEs: 8EXPL: 0

18 Mar 2004 — SQL injection vulnerability in search.php for Invision Board Forum allows remote attackers to execute arbitrary SQL queries via the st parameter. • http://marc.info/?l=bugtraq&m=107799527428834&w=2 •

CVSS: 9.8EPSS: 1%CPEs: 6EXPL: 1

03 Jan 2004 — SQL injection vulnerability in calendar.php for Invision Power Board 1.3 allows remote attackers to execute arbitrary SQL commands via the m parameter, which sets the $this->chosen_month variable. • http://forums.invisionpower.com/index.php?act=ST&f=1&t=108786 •

CVSS: 9.8EPSS: 2%CPEs: 1EXPL: 2

31 Dec 2003 — ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root_path parameter to reference a URL on a remote web server that contains the code. • https://www.exploit-db.com/exploits/22295 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 9.8EPSS: 0%CPEs: 6EXPL: 0

31 Dec 2003 — Invision Power Services Invision Board 1.0 through 1.1.1, when a forum is password protected, stores the administrator password in a cookie in plaintext, which could allow remote attackers to gain access. • http://securityreason.com/securityalert/3276 •