CVE-2006-0909: Medium severity Invision Power Services Invision Power Board vulnerability
Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to view sensitive information via a direct request to multiple PHP scripts that include the full path in error messages, including (1) PEAR/Text/Diff/Renderer/inline.php, (2) PEAR/Text/Diff/Renderer/unified.php, (3) PEAR/Text/Diff3.php, (4) classdb.php, (5) classdbmysql.php, and (6) classxml.php in the ipskernel/ directory; (7) mysqladminqueries.php, (8) mysqlextraqueries.php, (9) mysqlqueries.php, and (10) mysqlsubsmqueries.php in the sources/sql directory; (11) sources/acploaders/acppagescomponents.php; (12) sources/actionadmin/member.php and (13) sources/actionadmin/paysubscriptions.php; (14) login.php, (15) messenger.php, (16) moderate.php, (17) paysubscriptions.php, (18) register.php, (19) search.php, (20) topics.php, (21) and usercp.php in the sources/actionpublic directory; (22) bbcode/classbbcode.php, (23) bbcode/classbbcodelegacy.php, (24) editor/classeditorrte.php, (25) editor/classeditorstd.php, (26) post/classpost.php, (27) post/classpostedit.php, (28) post/classpostnew.php, (29) and post/classpostreply.php in the sources/classes directory; (30) sources/componentsacp/registrationDEPR.php; (31) sources/handlers/hanpaysubscriptions.php; (32) funcusercp.php; (33) searchmysqlftext.php, and (34) searchmysqlman.php in the sources/lib/ directory; and (35) convert/auth.php.bak, (36) external/auth.php, and (37) ldap/auth.php in the sources/loginauth directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0909?
CVE-2006-0909 is classified as a medium severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2006-0909?
To fix CVE-2006-0909, upgrade Invision Power Board to version 2.1.5 or later.
What versions of Invision Power Board are affected by CVE-2006-0909?
Versions 2.1.4 and earlier of Invision Power Board are affected by CVE-2006-0909.
What kind of information can be exposed in CVE-2006-0909?
CVE-2006-0909 can expose sensitive information through error messages from specific PHP scripts.
Is there a workaround for CVE-2006-0909?
A potential workaround for CVE-2006-0909 is to restrict direct access to the vulnerable PHP scripts through server configuration.