CVE-2006-0910: Medium severity Invision Power Services Invision Power Board vulnerability
Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to list directory contents via a direct request to multiple directories, including (1) sources/loginauth/convert/, (2) sources/portalplugins/, (3) cache/skincache/cacheid2/, (4) ipskernel/PEAR/, (5) ipskernel/PEAR/Text/, (6) ipskernel/PEAR/Text/Diff/, (7) ipskernel/PEAR/Text/Diff/Renderer/, (8) styleimages/1/folderrtefiles/, (9) styleimages/1/folderjsskin/, (10) styleimages/1/folderrteimages/, and (11) upgrade/ and its subdirectories.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0910?
CVE-2006-0910 is considered a medium severity vulnerability due to its potential impact on information disclosure.
How do I fix CVE-2006-0910?
To fix CVE-2006-0910, upgrade Invision Power Board to a version later than 2.1.4 that addresses this directory listing issue.
What version of Invision Power Board is affected by CVE-2006-0910?
Invision Power Board versions 2.1.4 and earlier are affected by CVE-2006-0910.
Can CVE-2006-0910 lead to further attacks?
Yes, CVE-2006-0910 can potentially expose sensitive directory contents, which could be leveraged for further attacks.
What kind of exploitation can occur due to CVE-2006-0910?
Exploitation of CVE-2006-0910 allows remote attackers to list directory contents, potentially exposing sensitive files or information.