Page 6 of 42 results (0.005 seconds)

CVSS: 5.0EPSS: 82%CPEs: 1EXPL: 1

action_public/search.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary PHP code via a search with a crafted value of the lastdate parameter, which alters the behavior of a regular expression to add a "#e" (execute) modifier. • https://www.exploit-db.com/exploits/1720 http://forums.invisionpower.com/index.php?showtopic=213374 http://secunia.com/advisories/19830 http://securityreason.com/securityalert/796 http://www.osvdb.org/25005 http://www.securityfocus.com/archive/1/431990/100/0/threaded http://www.securityfocus.com/archive/1/432226/100/0/threaded http://www.securityfocus.com/archive/1/432451/100/0/threaded http://www.securityfocus.com/archive/1/439607/100/0/threaded http://www.securityfocus. •

CVSS: 6.8EPSS: 15%CPEs: 3EXPL: 0

Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.1.5 and earlier before 20060308 allows remote attackers to inject arbitrary web script or HTML via a Private Message (PM) in certain circumstances. • http://forums.invisionpower.com/index.php?showtopic=209178 http://secunia.com/advisories/19299 http://www.securityfocus.com/bid/17187 http://www.vupen.com/english/advisories/2006/1044 https://exchange.xforce.ibmcloud.com/vulnerabilities/25384 •

CVSS: 4.3EPSS: 1%CPEs: 1EXPL: 8

Multiple cross-site scripting (XSS) vulnerabilities in Invision Power Board 2.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) result_type, (2) search_in, (3) nav, (4) forums, and (5) s parameters in the Search action to index.php; (6) st parameter to index.php with showtopics set to 1; (7) m, (8) y, and (9) d parameters in a calendar action; (10) t parameter in a Print action; (11) MID parameter in a Mail action; (12) HID parameter in a Help action; (13) active parameter in a search action; (14) sort_order, (15) max_results, or (16) sort_key parameter in a Members action. • https://www.exploit-db.com/exploits/27437 https://www.exploit-db.com/exploits/27438 https://www.exploit-db.com/exploits/27441 https://www.exploit-db.com/exploits/27440 https://www.exploit-db.com/exploits/27439 https://www.exploit-db.com/exploits/27436 https://www.exploit-db.com/exploits/27442 http://www.osvdb.org/25009 http://www.osvdb.org/25010 http://www.osvdb.org/25011 http://www.osvdb.org/25012 http://www.osvdb.org/25013 http://www.osvdb&# •

CVSS: 5.8EPSS: 0%CPEs: 2EXPL: 0

Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.0.4 and 2.1.4 before 20060130 allows remote attackers to steal cookies and probably conduct other activities when the victim is using Internet Explorer. • http://forums.invisionpower.com/index.php?showtopic=206790 http://secunia.com/advisories/19141 http://www.vupen.com/english/advisories/2006/0861 •

CVSS: 7.5EPSS: 4%CPEs: 2EXPL: 0

Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 2.0.4 and 2.1.4 before 20060105 allow remote attackers to execute arbitrary SQL commands via cookies, related to (1) arrays of id/stamp pairs and (2) the keys in arrays of key/value pairs in ipsclass.php; (3) the topics variable in usercp.php; and the topicsread cookie in (4) topics.php, (5) search.php, and (6) forums.php. • http://forums.invisionpower.com/index.php?act=Attach&type=post&id=9642 http://forums.invisionpower.com/index.php?showtopic=204627 http://secunia.com/advisories/19141 http://www.vupen.com/english/advisories/2006/0861 https://exchange.xforce.ibmcloud.com/vulnerabilities/25100 •