| VID |
21403 |
| Severity |
30 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
CGI |
| Detailed Description |
The Invision Power Board has an 'Arcade' Action SQL Injection Vulnerability. Invision Power Board is a PHP-based Web forum software package, distributed by Invision Power Services, Inc. Some IPB Systems running ibProArcade are vulnerable to a SQL Injection attack, caused by a failure of the application to properly validate user-supplied input in 'category' field prior to using it in an SQL query. By passing malicious SQL commands to the 'category' field, a remote attacker could execute to arbitrary code, including to add, modify or delete information in the backend database.
* References: http://www.securitytracker.com/alerts/2004/Nov/1012292.html http://archives.neohapsis.com/archives/bugtraq/2004-11/0264.html
* Platforms Affected: ibProArcade 2.5 and possible Any version Microsoft Windows Any version Unix Any version |
| Recommendation |
No upgrade or patch available as of June 2014.
Upgrade to the new version of ibProArcade, when new version fixed this problem becomes available from the ibProArcade Web site at http://www.ibproarcade.com/ |
| Related URL |
CVE-2004-1536 (CVE) |
| Related URL |
11719 (SecurityFocus) |
| Related URL |
18180 (ISS) |
|