CVE-2006-3544
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 1.3 Final allow remote attackers to execute arbitrary SQL commands via the CODE parameter in a (1) Stats, (2) Mail, and (3) Reg action in index.php. NOTE: the developer has disputed this issue, stating that "At no point does the CODE parameter touch the database. The CODE parameter is used in a SWITCH statement to determine which function to run.
** IMPUGNADA ** Múltiples vulnerabilidades de inyección SQL en Invision Power Board (IPB) 1.3 Final permiten a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro CODE de una acción (1) Stats, (2) Mail, y (3) Reg de index.php. NOTA: el desarrollador ha negado este problema, afirmando que "En ningún punto el parámetro CODE toca la base de datos. El parámetro CODE se usa en una sentencia SWITCH para determinar qué función ejecutar".
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-07-12 CVE Reserved
- 2006-07-13 CVE Published
- 2024-06-02 EPSS Updated
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://securityreason.com/securityalert/1225 | Third Party Advisory | |
http://www.osvdb.org/30084 | Vdb Entry | |
http://www.securityfocus.com/archive/1/438961/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/439629/100/0/threaded | Mailing List | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/27555 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://www.securityfocus.com/bid/18782 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Invision Power Services Search vendor "Invision Power Services" | Invision Board Search vendor "Invision Power Services" for product "Invision Board" | 1.3.1_final Search vendor "Invision Power Services" for product "Invision Board" and version "1.3.1_final" | - |
Affected
| ||||||
Invision Power Services Search vendor "Invision Power Services" | Invision Board Search vendor "Invision Power Services" for product "Invision Board" | 1.3_final Search vendor "Invision Power Services" for product "Invision Board" and version "1.3_final" | - |
Affected
|