// For flags

CVE-2006-3543

Invision Power Board (IP.Board) 1.x/2.x - Multiple SQL Injections

Severity Score

7.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 1.x and 2.x allow remote attackers to execute arbitrary SQL commands via the (1) idcat and (2) code parameters in a ketqua action in index.php; the id parameter in a (3) Attach and (4) ref action in index.php; the CODE parameter in a (5) Profile, (6) Login, and (7) Help action in index.php; and the (8) member_id parameter in coins_list.php. NOTE: the developer has disputed this issue, stating that the "CODE attribute is never present in an SQL query" and the "'ketqua' [action] and file 'coin_list.php' are not standard IPB 2.x features". It is unknown whether these vectors are associated with an independent module or modification of IPB

** IMPUGNADA ** Múltiples vulnerabilidades de inyección SQL en Invision Power Board (IPB) 1.x y 2.x permiten a atacantes remotos ejecutar comandos SQL de su elección a través de los parámetros (1) idcat y (2) code en una acción ketqua de index.php; el parámetro id en una acción (3) Attach y (4) ref de index.php; el parámetro CODE en una acción (5) Profile, (6) Login, y (7) Help de index.php; y el parámetro (8) member_id de coins_list.php. NOTA: el desarrollador ha negado este problema, afirmando que "el atributo CODE no está presente en una consulta SQL" y "[la acción] 'ketqua' y el archivo 'coin_list.php' no son funcionalidades estándar de IPB 2.x". Se desconoce si estos vectores están asociados con un módulo independiente o una modificación de IPB.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2006-07-05 First Exploit
  • 2006-07-12 CVE Reserved
  • 2006-07-13 CVE Published
  • 2024-06-02 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Invision Power Services
Search vendor "Invision Power Services"
Invision Power Board
Search vendor "Invision Power Services" for product "Invision Power Board"
1.0
Search vendor "Invision Power Services" for product "Invision Power Board" and version "1.0"
-
Affected
Invision Power Services
Search vendor "Invision Power Services"
Invision Power Board
Search vendor "Invision Power Services" for product "Invision Power Board"
1.0.1
Search vendor "Invision Power Services" for product "Invision Power Board" and version "1.0.1"
-
Affected
Invision Power Services
Search vendor "Invision Power Services"
Invision Power Board
Search vendor "Invision Power Services" for product "Invision Power Board"
1.0.3
Search vendor "Invision Power Services" for product "Invision Power Board" and version "1.0.3"
-
Affected
Invision Power Services
Search vendor "Invision Power Services"
Invision Power Board
Search vendor "Invision Power Services" for product "Invision Power Board"
1.1.1
Search vendor "Invision Power Services" for product "Invision Power Board" and version "1.1.1"
-
Affected
Invision Power Services
Search vendor "Invision Power Services"
Invision Power Board
Search vendor "Invision Power Services" for product "Invision Power Board"
1.1.2
Search vendor "Invision Power Services" for product "Invision Power Board" and version "1.1.2"
-
Affected
Invision Power Services
Search vendor "Invision Power Services"
Invision Power Board
Search vendor "Invision Power Services" for product "Invision Power Board"
1.2
Search vendor "Invision Power Services" for product "Invision Power Board" and version "1.2"
-
Affected
Invision Power Services
Search vendor "Invision Power Services"
Invision Power Board
Search vendor "Invision Power Services" for product "Invision Power Board"
1.3
Search vendor "Invision Power Services" for product "Invision Power Board" and version "1.3"
-
Affected
Invision Power Services
Search vendor "Invision Power Services"
Invision Power Board
Search vendor "Invision Power Services" for product "Invision Power Board"
1.3.1_final
Search vendor "Invision Power Services" for product "Invision Power Board" and version "1.3.1_final"
-
Affected
Invision Power Services
Search vendor "Invision Power Services"
Invision Power Board
Search vendor "Invision Power Services" for product "Invision Power Board"
1.3_final
Search vendor "Invision Power Services" for product "Invision Power Board" and version "1.3_final"
-
Affected
Invision Power Services
Search vendor "Invision Power Services"
Invision Power Board
Search vendor "Invision Power Services" for product "Invision Power Board"
2.0
Search vendor "Invision Power Services" for product "Invision Power Board" and version "2.0"
-
Affected
Invision Power Services
Search vendor "Invision Power Services"
Invision Power Board
Search vendor "Invision Power Services" for product "Invision Power Board"
2.0.1
Search vendor "Invision Power Services" for product "Invision Power Board" and version "2.0.1"
-
Affected
Invision Power Services
Search vendor "Invision Power Services"
Invision Power Board
Search vendor "Invision Power Services" for product "Invision Power Board"
2.0.2
Search vendor "Invision Power Services" for product "Invision Power Board" and version "2.0.2"
-
Affected
Invision Power Services
Search vendor "Invision Power Services"
Invision Power Board
Search vendor "Invision Power Services" for product "Invision Power Board"
2.0.3
Search vendor "Invision Power Services" for product "Invision Power Board" and version "2.0.3"
-
Affected
Invision Power Services
Search vendor "Invision Power Services"
Invision Power Board
Search vendor "Invision Power Services" for product "Invision Power Board"
2.0.4
Search vendor "Invision Power Services" for product "Invision Power Board" and version "2.0.4"
-
Affected
Invision Power Services
Search vendor "Invision Power Services"
Invision Power Board
Search vendor "Invision Power Services" for product "Invision Power Board"
2.0_alpha3
Search vendor "Invision Power Services" for product "Invision Power Board" and version "2.0_alpha3"
-
Affected
Invision Power Services
Search vendor "Invision Power Services"
Invision Power Board
Search vendor "Invision Power Services" for product "Invision Power Board"
2.0_pdr3
Search vendor "Invision Power Services" for product "Invision Power Board" and version "2.0_pdr3"
-
Affected
Invision Power Services
Search vendor "Invision Power Services"
Invision Power Board
Search vendor "Invision Power Services" for product "Invision Power Board"
2.0_pf1
Search vendor "Invision Power Services" for product "Invision Power Board" and version "2.0_pf1"
-
Affected
Invision Power Services
Search vendor "Invision Power Services"
Invision Power Board
Search vendor "Invision Power Services" for product "Invision Power Board"
2.0_pf2
Search vendor "Invision Power Services" for product "Invision Power Board" and version "2.0_pf2"
-
Affected
Invision Power Services
Search vendor "Invision Power Services"
Invision Power Board
Search vendor "Invision Power Services" for product "Invision Power Board"
2.1
Search vendor "Invision Power Services" for product "Invision Power Board" and version "2.1"
-
Affected
Invision Power Services
Search vendor "Invision Power Services"
Invision Power Board
Search vendor "Invision Power Services" for product "Invision Power Board"
2.1.4
Search vendor "Invision Power Services" for product "Invision Power Board" and version "2.1.4"
-
Affected
Invision Power Services
Search vendor "Invision Power Services"
Invision Power Board
Search vendor "Invision Power Services" for product "Invision Power Board"
2.1.5
Search vendor "Invision Power Services" for product "Invision Power Board" and version "2.1.5"
-
Affected
Invision Power Services
Search vendor "Invision Power Services"
Invision Power Board
Search vendor "Invision Power Services" for product "Invision Power Board"
2.1.6
Search vendor "Invision Power Services" for product "Invision Power Board" and version "2.1.6"
-
Affected
Invision Power Services
Search vendor "Invision Power Services"
Invision Power Board
Search vendor "Invision Power Services" for product "Invision Power Board"
2.1_alpha2
Search vendor "Invision Power Services" for product "Invision Power Board" and version "2.1_alpha2"
-
Affected