Page 6 of 58 results (0.013 seconds)

CVSS: 5.0EPSS: 82%CPEs: 1EXPL: 1

action_public/search.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary PHP code via a search with a crafted value of the lastdate parameter, which alters the behavior of a regular expression to add a "#e" (execute) modifier. • https://www.exploit-db.com/exploits/1720 http://forums.invisionpower.com/index.php?showtopic=213374 http://secunia.com/advisories/19830 http://securityreason.com/securityalert/796 http://www.osvdb.org/25005 http://www.securityfocus.com/archive/1/431990/100/0/threaded http://www.securityfocus.com/archive/1/432226/100/0/threaded http://www.securityfocus.com/archive/1/432451/100/0/threaded http://www.securityfocus.com/archive/1/439607/100/0/threaded http://www.securityfocus. •

CVSS: 5.0EPSS: 3%CPEs: 13EXPL: 1

SQL injection vulnerability in lib/func_taskmanager.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary SQL commands via the ck parameter, which can inject at most 32 characters. • https://www.exploit-db.com/exploits/27736 http://forums.invisionpower.com/index.php?showtopic=213374 http://secunia.com/advisories/19830 http://securityreason.com/securityalert/796 http://www.securityfocus.com/archive/1/431990/100/0/threaded http://www.securityfocus.com/archive/1/432226/100/0/threaded http://www.securityfocus.com/bid/17690 http://www.vupen.com/english/advisories/2006/1534 https://exchange.xforce.ibmcloud.com/vulnerabilities/26071 •

CVSS: 6.8EPSS: 15%CPEs: 3EXPL: 0

Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.1.5 and earlier before 20060308 allows remote attackers to inject arbitrary web script or HTML via a Private Message (PM) in certain circumstances. • http://forums.invisionpower.com/index.php?showtopic=209178 http://secunia.com/advisories/19299 http://www.securityfocus.com/bid/17187 http://www.vupen.com/english/advisories/2006/1044 https://exchange.xforce.ibmcloud.com/vulnerabilities/25384 •

CVSS: 4.3EPSS: 1%CPEs: 1EXPL: 8

Multiple cross-site scripting (XSS) vulnerabilities in Invision Power Board 2.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) result_type, (2) search_in, (3) nav, (4) forums, and (5) s parameters in the Search action to index.php; (6) st parameter to index.php with showtopics set to 1; (7) m, (8) y, and (9) d parameters in a calendar action; (10) t parameter in a Print action; (11) MID parameter in a Mail action; (12) HID parameter in a Help action; (13) active parameter in a search action; (14) sort_order, (15) max_results, or (16) sort_key parameter in a Members action. • https://www.exploit-db.com/exploits/27437 https://www.exploit-db.com/exploits/27438 https://www.exploit-db.com/exploits/27441 https://www.exploit-db.com/exploits/27440 https://www.exploit-db.com/exploits/27439 https://www.exploit-db.com/exploits/27436 https://www.exploit-db.com/exploits/27442 http://www.osvdb.org/25009 http://www.osvdb.org/25010 http://www.osvdb.org/25011 http://www.osvdb.org/25012 http://www.osvdb.org/25013 http://www.osvdb&# •

CVSS: 7.5EPSS: 4%CPEs: 2EXPL: 0

Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 2.0.4 and 2.1.4 before 20060105 allow remote attackers to execute arbitrary SQL commands via cookies, related to (1) arrays of id/stamp pairs and (2) the keys in arrays of key/value pairs in ipsclass.php; (3) the topics variable in usercp.php; and the topicsread cookie in (4) topics.php, (5) search.php, and (6) forums.php. • http://forums.invisionpower.com/index.php?act=Attach&type=post&id=9642 http://forums.invisionpower.com/index.php?showtopic=204627 http://secunia.com/advisories/19141 http://www.vupen.com/english/advisories/2006/0861 https://exchange.xforce.ibmcloud.com/vulnerabilities/25100 •