Korean
<< Back
VID 21403
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The Invision Power Board has an 'Arcade' Action SQL Injection Vulnerability.
Invision Power Board is a PHP-based Web forum software package, distributed by Invision Power Services, Inc. Some IPB Systems running ibProArcade are vulnerable to a SQL Injection attack, caused by a failure of the application to properly validate user-supplied input in 'category' field prior to using it in an SQL query. By passing malicious SQL commands to the 'category' field, a remote attacker could execute to arbitrary code, including to add, modify or delete information in the backend database.

* References:
http://www.securitytracker.com/alerts/2004/Nov/1012292.html
http://archives.neohapsis.com/archives/bugtraq/2004-11/0264.html

* Platforms Affected:
ibProArcade 2.5 and possible Any version
Microsoft Windows Any version
Unix Any version
Recommendation No upgrade or patch available as of June 2014.

Upgrade to the new version of ibProArcade, when new version fixed this problem becomes available from the ibProArcade Web site at http://www.ibproarcade.com/
Related URL CVE-2004-1536 (CVE)
Related URL 11719 (SecurityFocus)
Related URL 18180 (ISS)