Korean
<< Back
VID 21402
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The Invision Power Board has a 'POST' Action SQL Injection Vulnerability.
Invision Power Board is a PHP-based Web forum software package, distributed by Invision Power Services, Inc. Some Invision Power Board versions are vulnerable to a SQL Injection attack, caused by a failure of the application to properly validate user-supplied input prior to using it in an SQL query. By passing malicious SQL commands to the 'post.php' script, a remote attacker could execute to arbitrary code, including to add, modify or delete information in the backend database.

* References:
http://www.securityfocus.com/archive/1/381503

* Platforms Affected:
Invision Power Board 2.0.0
Invision Power Board 2.0.1
Invision Power Board 2.0.2
Any Operating system Any version
Recommendation Apply the update for this vulnerability, available from the Invision Power Services Update dated Nov 12 2004, 09:56 PM at http://forums.invisionpower.com/index.php?showtopic=154916
Related URL CVE-2004-1531 (CVE)
Related URL 11703 (SecurityFocus)
Related URL 18164 (ISS)