CVE-2006-2059: Medium severity invision power services invision power board vulnerability
actionpublic/search.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary PHP code via a search with a crafted value of the lastdate parameter, which alters the behavior of a regular expression to add a "#e" (execute) modifier.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2059?
CVE-2006-2059 is classified as a critical vulnerability due to its ability to allow remote code execution.
How do I fix CVE-2006-2059?
To fix CVE-2006-2059, it is recommended to update Invision Power Board to the latest version that has addressed this vulnerability.
What versions of Invision Power Board are affected by CVE-2006-2059?
CVE-2006-2059 affects Invision Power Board versions 2.1.x and 2.0.x prior to the patch released on 20060425.
Can CVE-2006-2059 be exploited remotely?
Yes, CVE-2006-2059 can be exploited remotely by attackers using a crafted value in the lastdate parameter.
What impact does CVE-2006-2059 have on my website?
CVE-2006-2059 can lead to arbitrary PHP code execution, compromising the security of your website.