First published: Thu Mar 09 2006(Updated: )
SQL injection vulnerability in index.php, possibly during a showtopic operation, in Invision Power Board (IPB) 2.1.5 allows remote attackers to execute arbitrary SQL commands via the st parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Invision Power Board | =2.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1076 is considered a critical vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
To fix CVE-2006-1076, upgrade Invision Power Board to a version that addresses this SQL injection flaw.
The potential impacts of CVE-2006-1076 include unauthorized access to the database and data manipulation by attackers.
CVE-2006-1076 specifically affects Invision Power Board version 2.1.5 and may not be applicable to other versions.
The cause of CVE-2006-1076 is an SQL injection vulnerability in the index.php file during the showtopic operation.