
CVE-2005-1946
https://notcve.org/view.php?id=CVE-2005-1946
09 Jun 2005 — Multiple SQL injection vulnerabilities in Invision Blog before 1.1.2 Final allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to an editentry, replyentry, or editcomment action, or (2) the mid parameter to an aboutme action. • http://marc.info/?l=bugtraq&m=111833601302752&w=2 •

CVE-2005-1948 – Invision Power Services Invision Gallery 1.0.1/1.3 - SQL Injection
https://notcve.org/view.php?id=CVE-2005-1948
09 Jun 2005 — Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL commands via (1) the comment parameter in an editcomment action or (2) the rating parameter when voting on a photo. • https://www.exploit-db.com/exploits/25806 •

CVE-2005-1816
https://notcve.org/view.php?id=CVE-2005-1816
01 Jun 2005 — Invision Power Board (IPB) 1.0 through 2.0.4 allows non-root admins to add themselves or other users to the root admin group via the "Move users in this group to" screen. • http://archives.neohapsis.com/archives/fulldisclosure/2005-05/0635.html •

CVE-2005-1817 – Invision Power Board 1.x - Unauthorized Access
https://notcve.org/view.php?id=CVE-2005-1817
01 Jun 2005 — Invision Power Board (IPB) 1.0 through 1.3 allows remote attackers to edit arbitrary forum posts via a direct request to index.php with modified parameters. • https://www.exploit-db.com/exploits/25741 •

CVE-2005-1597 – Invision Power Board (IP.Board) < 2.0.3 - Multiple Vulnerabilities
https://notcve.org/view.php?id=CVE-2005-1597
16 May 2005 — Cross-site scripting (XSS) vulnerability in (1) search.php and (2) topics.php for Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the highlite parameter. • https://www.exploit-db.com/exploits/43824 •

CVE-2005-1598 – Invision Power Board 2.0.3 - 'login.php' SQL Injection
https://notcve.org/view.php?id=CVE-2005-1598
16 May 2005 — SQL injection vulnerability in Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via a crafted cookie password hash (pass_hash) that modifies the internal $pid variable. • https://www.exploit-db.com/exploits/1013 •

CVE-2005-1443
https://notcve.org/view.php?id=CVE-2005-1443
03 May 2005 — Multiple cross-site scripting (XSS) vulnerabilities in index.php for Invision Power Board (IPB) 2.0.3 and 2.1 Alpha 2 allows remote attackers to inject arbitrary web script or HTML via the (1) act, (2) Members, (3) calendar, or (4) HID parameters. • http://securitytracker.com/id?1013863 •

CVE-2005-1070 – Invision Power Board 1.x - 'ST' SQL Injection
https://notcve.org/view.php?id=CVE-2005-1070
11 Apr 2005 — SQL injection vulnerability in index.php in Invision Power Board 1.3.1 Final and earlier allows remote attackers to execute arbitrary SQL commands via the st parameter. • https://www.exploit-db.com/exploits/25380 •

CVE-2005-0886 – Invision Power Board 1.x/2.0 - HTML Injection
https://notcve.org/view.php?id=CVE-2005-0886
26 Mar 2005 — Cross-site scripting (XSS) vulnerability in Invision Power Board 2.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an HTTP POST request. • https://www.exploit-db.com/exploits/25267 •

CVE-2005-0477 – Invision Power Board (IP.Board) 1.x/2.0.3 - SML Code Script Injection
https://notcve.org/view.php?id=CVE-2005-0477
19 Feb 2005 — Cross-site scripting (XSS) vulnerability in the SML code for Invision Power Board 1.3.1 FINAL allows remote attackers to inject arbitrary web script via (1) a signature file or (2) a message post containing an IMG tag within a COLOR tag whose style is set to background:url. Vulnerabilidad de secuencias de comandos en sitios cruzados en el código SML de Invision Power Board 1.3.1 FINAL permite a atacantes remotos la inyección de sripts arbitrarios mediante: un fichero de firmas, un mensaje que contiene una e... • https://www.exploit-db.com/exploits/25143 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •