CVE-2006-3543: SQL Injection
DISPUTED Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 1.x and 2.x allow remote attackers to execute arbitrary SQL commands via the (1) idcat and (2) code parameters in a ketqua action in index.php; the id parameter in a (3) Attach and (4) ref action in index.php; the CODE parameter in a (5) Profile, (6) Login, and (7) Help action in index.php; and the (8) memberid parameter in coinslist.php. NOTE: the developer has disputed this issue, stating that the "CODE attribute is never present in an SQL query" and the "'ketqua' [action] and file 'coinlist.php' are not standard IPB 2.x features". It is unknown whether these vectors are associated with an independent module or modification of IPB.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3543?
CVE-2006-3543 is classified as a high-severity vulnerability due to its potential for remote SQL injection attacks.
How do I fix CVE-2006-3543?
To resolve CVE-2006-3543, update Invision Power Board to the latest secured version that addresses these SQL injection vulnerabilities.
Which versions of Invision Power Board are affected by CVE-2006-3543?
CVE-2006-3543 affects multiple versions of Invision Power Board including 1.x and 2.x series.
Can CVE-2006-3543 lead to data breaches?
Yes, CVE-2006-3543 can allow remote attackers to execute arbitrary SQL commands, potentially leading to data breaches.
How can I identify if my Invision Power Board installation is vulnerable to CVE-2006-3543?
To identify susceptibility to CVE-2006-3543, review server logs for unusual SQL queries and check if you are running an affected version of Invision Power Board.