First published: Fri May 05 2006(Updated: )
SQL injection vulnerability in index.php in Invision Power Board allows remote attackers to execute arbitrary SQL commands via the pid parameter in a reputation action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Invision Power Board | =2.0.0 | |
Invision Power Board | =2.0.1 | |
Invision Power Board | =2.0.2 | |
Invision Power Board | =2.0.3 | |
Invision Power Board | =2.0.4 | |
Invision Power Board | =2.1 | |
Invision Power Board | =2.1.4 | |
Invision Power Board | =2.1.5 | |
Invision Power Board | =2.1.6 | |
Invision Power Board | =2.1_alpha2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2217 is considered to be a critical vulnerability due to the potential for arbitrary SQL command execution.
To fix CVE-2006-2217, upgrade Invision Power Board to a safe version that has addressed this SQL injection vulnerability.
CVE-2006-2217 affects Invision Power Board versions 2.0.0 to 2.1.6 inclusive.
CVE-2006-2217 is an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
Remote attackers with access to the index.php file and the ability to manipulate the pid parameter can exploit CVE-2006-2217.