CVE-2004-1531: SQL Injection
Published Dec 31, 2004
·Updated
SQL injection vulnerability in post.php in Invision Power Board (IPB) 2.0.0 through 2.0.2 allows remote attackers to execute arbitrary SQL commands via the qpid parameter.
Affected Software
3 affected components
Invision Power Services Invision Board=2.0.1
Invision Power Services Invision Board=2.0.2
Invision Power Services Invision Board=2.0
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Feb 19, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1531?
CVE-2004-1531 is classified as a high severity vulnerability due to its potential to allow remote SQL injection attacks.
2
How do I fix CVE-2004-1531?
To fix CVE-2004-1531, upgrade Invision Power Board to version 2.0.3 or later.
3
What software versions are affected by CVE-2004-1531?
CVE-2004-1531 affects Invision Power Board versions 2.0.0 through 2.0.2.
4
What type of attack does CVE-2004-1531 enable?
CVE-2004-1531 enables remote attackers to execute arbitrary SQL commands through the qpid parameter.
5
Is CVE-2004-1531 a common vulnerability?
CVE-2004-1531 is a known SQL injection vulnerability commonly discussed in security forums due to its impact on web applications.