First published: Tue May 09 2006(Updated: )
SQL injection vulnerability in the do_mmod function in mod.php in Invision Community Blog (ICB) 1.1.2 final through 1.2 allows remote attackers with moderator privileges to execute arbitrary SQL commands via the selectedbids parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Invision Community | =1.0 | |
Invision Community | =1.1 | |
Invision Community | =1.1.2_final | |
Invision Community | =1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2251 is considered a high severity vulnerability due to the potential for remote attackers to execute arbitrary SQL commands.
To fix CVE-2006-2251, upgrade to a version of Invision Community Blog that is not affected, such as version 1.2 or later.
CVE-2006-2251 affects Invision Community Blog versions 1.0, 1.1, 1.1.2 final, and 1.2.
Remote attackers with moderator privileges can exploit CVE-2006-2251 to perform SQL injection attacks.
CVE-2006-2251 can enable attackers to execute arbitrary SQL commands, potentially compromising the integrity and confidentiality of the database.