CVE-2006-3543
Invision Power Board (IP.Board) 1.x/2.x - Multiple SQL Injections
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 1.x and 2.x allow remote attackers to execute arbitrary SQL commands via the (1) idcat and (2) code parameters in a ketqua action in index.php; the id parameter in a (3) Attach and (4) ref action in index.php; the CODE parameter in a (5) Profile, (6) Login, and (7) Help action in index.php; and the (8) member_id parameter in coins_list.php. NOTE: the developer has disputed this issue, stating that the "CODE attribute is never present in an SQL query" and the "'ketqua' [action] and file 'coin_list.php' are not standard IPB 2.x features". It is unknown whether these vectors are associated with an independent module or modification of IPB
** IMPUGNADA ** Múltiples vulnerabilidades de inyección SQL en Invision Power Board (IPB) 1.x y 2.x permiten a atacantes remotos ejecutar comandos SQL de su elección a través de los parámetros (1) idcat y (2) code en una acción ketqua de index.php; el parámetro id en una acción (3) Attach y (4) ref de index.php; el parámetro CODE en una acción (5) Profile, (6) Login, y (7) Help de index.php; y el parámetro (8) member_id de coins_list.php. NOTA: el desarrollador ha negado este problema, afirmando que "el atributo CODE no está presente en una consulta SQL" y "[la acción] 'ketqua' y el archivo 'coin_list.php' no son funcionalidades estándar de IPB 2.x". Se desconoce si estos vectores están asociados con un módulo independiente o una modificación de IPB.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-07-05 First Exploit
- 2006-07-12 CVE Reserved
- 2006-07-13 CVE Published
- 2024-06-02 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://securityreason.com/securityalert/1231 | Third Party Advisory | |
http://www.osvdb.org/30084 | Vdb Entry | |
http://www.securityfocus.com/archive/1/439145/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/439602/100/0/threaded | Mailing List |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/28167 | 2006-07-05 | |
http://www.securityfocus.com/bid/18836 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Invision Power Services Search vendor "Invision Power Services" | Invision Power Board Search vendor "Invision Power Services" for product "Invision Power Board" | 1.0 Search vendor "Invision Power Services" for product "Invision Power Board" and version "1.0" | - |
Affected
| ||||||
Invision Power Services Search vendor "Invision Power Services" | Invision Power Board Search vendor "Invision Power Services" for product "Invision Power Board" | 1.0.1 Search vendor "Invision Power Services" for product "Invision Power Board" and version "1.0.1" | - |
Affected
| ||||||
Invision Power Services Search vendor "Invision Power Services" | Invision Power Board Search vendor "Invision Power Services" for product "Invision Power Board" | 1.0.3 Search vendor "Invision Power Services" for product "Invision Power Board" and version "1.0.3" | - |
Affected
| ||||||
Invision Power Services Search vendor "Invision Power Services" | Invision Power Board Search vendor "Invision Power Services" for product "Invision Power Board" | 1.1.1 Search vendor "Invision Power Services" for product "Invision Power Board" and version "1.1.1" | - |
Affected
| ||||||
Invision Power Services Search vendor "Invision Power Services" | Invision Power Board Search vendor "Invision Power Services" for product "Invision Power Board" | 1.1.2 Search vendor "Invision Power Services" for product "Invision Power Board" and version "1.1.2" | - |
Affected
| ||||||
Invision Power Services Search vendor "Invision Power Services" | Invision Power Board Search vendor "Invision Power Services" for product "Invision Power Board" | 1.2 Search vendor "Invision Power Services" for product "Invision Power Board" and version "1.2" | - |
Affected
| ||||||
Invision Power Services Search vendor "Invision Power Services" | Invision Power Board Search vendor "Invision Power Services" for product "Invision Power Board" | 1.3 Search vendor "Invision Power Services" for product "Invision Power Board" and version "1.3" | - |
Affected
| ||||||
Invision Power Services Search vendor "Invision Power Services" | Invision Power Board Search vendor "Invision Power Services" for product "Invision Power Board" | 1.3.1_final Search vendor "Invision Power Services" for product "Invision Power Board" and version "1.3.1_final" | - |
Affected
| ||||||
Invision Power Services Search vendor "Invision Power Services" | Invision Power Board Search vendor "Invision Power Services" for product "Invision Power Board" | 1.3_final Search vendor "Invision Power Services" for product "Invision Power Board" and version "1.3_final" | - |
Affected
| ||||||
Invision Power Services Search vendor "Invision Power Services" | Invision Power Board Search vendor "Invision Power Services" for product "Invision Power Board" | 2.0 Search vendor "Invision Power Services" for product "Invision Power Board" and version "2.0" | - |
Affected
| ||||||
Invision Power Services Search vendor "Invision Power Services" | Invision Power Board Search vendor "Invision Power Services" for product "Invision Power Board" | 2.0.1 Search vendor "Invision Power Services" for product "Invision Power Board" and version "2.0.1" | - |
Affected
| ||||||
Invision Power Services Search vendor "Invision Power Services" | Invision Power Board Search vendor "Invision Power Services" for product "Invision Power Board" | 2.0.2 Search vendor "Invision Power Services" for product "Invision Power Board" and version "2.0.2" | - |
Affected
| ||||||
Invision Power Services Search vendor "Invision Power Services" | Invision Power Board Search vendor "Invision Power Services" for product "Invision Power Board" | 2.0.3 Search vendor "Invision Power Services" for product "Invision Power Board" and version "2.0.3" | - |
Affected
| ||||||
Invision Power Services Search vendor "Invision Power Services" | Invision Power Board Search vendor "Invision Power Services" for product "Invision Power Board" | 2.0.4 Search vendor "Invision Power Services" for product "Invision Power Board" and version "2.0.4" | - |
Affected
| ||||||
Invision Power Services Search vendor "Invision Power Services" | Invision Power Board Search vendor "Invision Power Services" for product "Invision Power Board" | 2.0_alpha3 Search vendor "Invision Power Services" for product "Invision Power Board" and version "2.0_alpha3" | - |
Affected
| ||||||
Invision Power Services Search vendor "Invision Power Services" | Invision Power Board Search vendor "Invision Power Services" for product "Invision Power Board" | 2.0_pdr3 Search vendor "Invision Power Services" for product "Invision Power Board" and version "2.0_pdr3" | - |
Affected
| ||||||
Invision Power Services Search vendor "Invision Power Services" | Invision Power Board Search vendor "Invision Power Services" for product "Invision Power Board" | 2.0_pf1 Search vendor "Invision Power Services" for product "Invision Power Board" and version "2.0_pf1" | - |
Affected
| ||||||
Invision Power Services Search vendor "Invision Power Services" | Invision Power Board Search vendor "Invision Power Services" for product "Invision Power Board" | 2.0_pf2 Search vendor "Invision Power Services" for product "Invision Power Board" and version "2.0_pf2" | - |
Affected
| ||||||
Invision Power Services Search vendor "Invision Power Services" | Invision Power Board Search vendor "Invision Power Services" for product "Invision Power Board" | 2.1 Search vendor "Invision Power Services" for product "Invision Power Board" and version "2.1" | - |
Affected
| ||||||
Invision Power Services Search vendor "Invision Power Services" | Invision Power Board Search vendor "Invision Power Services" for product "Invision Power Board" | 2.1.4 Search vendor "Invision Power Services" for product "Invision Power Board" and version "2.1.4" | - |
Affected
| ||||||
Invision Power Services Search vendor "Invision Power Services" | Invision Power Board Search vendor "Invision Power Services" for product "Invision Power Board" | 2.1.5 Search vendor "Invision Power Services" for product "Invision Power Board" and version "2.1.5" | - |
Affected
| ||||||
Invision Power Services Search vendor "Invision Power Services" | Invision Power Board Search vendor "Invision Power Services" for product "Invision Power Board" | 2.1.6 Search vendor "Invision Power Services" for product "Invision Power Board" and version "2.1.6" | - |
Affected
| ||||||
Invision Power Services Search vendor "Invision Power Services" | Invision Power Board Search vendor "Invision Power Services" for product "Invision Power Board" | 2.1_alpha2 Search vendor "Invision Power Services" for product "Invision Power Board" and version "2.1_alpha2" | - |
Affected
|