CVE-2006-1267: Medium severity Invision Power Services Invision Power Board vulnerability
Invision Power Board 2.1.4 allows remote attackers to hijack sessions and possibly gain administrative privileges by obtaining the session ID from the s parameter, then replaying it in another request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1267?
CVE-2006-1267 is considered a high-severity vulnerability due to the potential for session hijacking and unauthorized administrative access.
How do I fix CVE-2006-1267?
To fix CVE-2006-1267, you should upgrade Invision Power Board to a patched version that addresses the session ID vulnerability.
What versions of Invision Power Board are affected by CVE-2006-1267?
CVE-2006-1267 specifically affects Invision Power Board version 2.1.4.
What type of attack does CVE-2006-1267 enable?
CVE-2006-1267 enables remote attackers to perform session hijacking, allowing them to impersonate legitimate users.
Can CVE-2006-1267 be exploited without authentication?
Yes, CVE-2006-1267 can be exploited by remote attackers without needing prior authentication to hijack user sessions.