
CVE-2006-2498
https://notcve.org/view.php?id=CVE-2006-2498
20 May 2006 — Invision Power Board (IPB) before 2.1.6 allows remote attackers to execute arbitrary PHP script via attack vectors involving (1) the post_icon variable in classes/post/class_post.php and (2) the df value in action_public/moderate.php. • http://attrition.org/pipermail/vim/2006-May/000776.html •

CVE-2006-2204
https://notcve.org/view.php?id=CVE-2006-2204
05 May 2006 — SQL injection vulnerability in the topic deletion functionality (post_delete function in func_mod.php) for Invision Power Board 2.1.5 allows remote authenticated moderators to execute arbitrary SQL commands via the selectedpids parameter, which bypasses an integer value check when the $id variable is an array. • http://forums.invisionpower.com/index.php?showtopic=214248&view=getnewpo •

CVE-2006-2217 – Invision Power Board 2.0/2.1 - 'index.php' SQL Injection
https://notcve.org/view.php?id=CVE-2006-2217
05 May 2006 — SQL injection vulnerability in index.php in Invision Power Board allows remote attackers to execute arbitrary SQL commands via the pid parameter in a reputation action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. • https://www.exploit-db.com/exploits/27818 •

CVE-2006-2059 – Invision Power Board 2.1.5 - 'lastdate' Remote Code Execution
https://notcve.org/view.php?id=CVE-2006-2059
26 Apr 2006 — action_public/search.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary PHP code via a search with a crafted value of the lastdate parameter, which alters the behavior of a regular expression to add a "#e" (execute) modifier. • https://www.exploit-db.com/exploits/1720 •

CVE-2006-2061 – Invision Power Board 2.0/2.1 - 'index.php?CK' SQL Injection
https://notcve.org/view.php?id=CVE-2006-2061
26 Apr 2006 — SQL injection vulnerability in lib/func_taskmanager.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary SQL commands via the ck parameter, which can inject at most 32 characters. • https://www.exploit-db.com/exploits/27736 •

CVE-2006-1369
https://notcve.org/view.php?id=CVE-2006-1369
23 Mar 2006 — Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.1.5 and earlier before 20060308 allows remote attackers to inject arbitrary web script or HTML via a Private Message (PM) in certain circumstances. • http://forums.invisionpower.com/index.php?showtopic=209178 •

CVE-2006-1076 – Invision Power Board 2.1.5 - showtopic SQL Injection
https://notcve.org/view.php?id=CVE-2006-1076
09 Mar 2006 — SQL injection vulnerability in index.php, possibly during a showtopic operation, in Invision Power Board (IPB) 2.1.5 allows remote attackers to execute arbitrary SQL commands via the st parameter. • https://www.exploit-db.com/exploits/27361 •

CVE-2005-2542 – Invision Power Board (IP.Board) 1.0.3 - Attached File Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2005-2542
10 Aug 2005 — Invision Power Board (IPB) 1.0.3 allows remote attackers to inject arbitrary web script or HTML via an attachment, which is automatically downloaded and processed as HTML. • https://www.exploit-db.com/exploits/26104 •