| VID |
21402 |
| Severity |
30 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
CGI |
| Detailed Description |
The Invision Power Board has a 'POST' Action SQL Injection Vulnerability. Invision Power Board is a PHP-based Web forum software package, distributed by Invision Power Services, Inc. Some Invision Power Board versions are vulnerable to a SQL Injection attack, caused by a failure of the application to properly validate user-supplied input prior to using it in an SQL query. By passing malicious SQL commands to the 'post.php' script, a remote attacker could execute to arbitrary code, including to add, modify or delete information in the backend database.
* References: http://www.securityfocus.com/archive/1/381503
* Platforms Affected: Invision Power Board 2.0.0 Invision Power Board 2.0.1 Invision Power Board 2.0.2 Any Operating system Any version |
| Recommendation |
Apply the update for this vulnerability, available from the Invision Power Services Update dated Nov 12 2004, 09:56 PM at http://forums.invisionpower.com/index.php?showtopic=154916 |
| Related URL |
CVE-2004-1531 (CVE) |
| Related URL |
11703 (SecurityFocus) |
| Related URL |
18164 (ISS) |
|