CVE-2006-7071: SQL Injection
Published Feb 27, 2007
·Updated
SQL injection vulnerability in classes/classsession.php in Invision Power Board (IPB) 2.1 up to 2.1.6 allows remote attackers to execute arbitrary SQL commands via the CLIENTIP parameter.
Affected Software
6 affected components
Invision Power Services Invision Power Board=2.1.1
Invision Power Services Invision Power Board=2.1.6
Invision Power Services Invision Power Board=2.1.2
Invision Power Services Invision Power Board=2.1.3
Invision Power Services Invision Power Board=2.1.5
Invision Power Services Invision Power Board=2.1.4
Remediation
Patch Available
Event History
Feb 27, 2007
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-7071?
CVE-2006-7071 is considered a critical vulnerability due to its ability to allow remote attackers to execute arbitrary SQL commands.
2
How do I fix CVE-2006-7071?
To fix CVE-2006-7071, upgrade Invision Power Board to version 2.1.7 or later, which addresses this SQL injection vulnerability.
3
Which versions are affected by CVE-2006-7071?
CVE-2006-7071 affects Invision Power Board versions 2.1.1 to 2.1.6.
4
What type of vulnerability is CVE-2006-7071?
CVE-2006-7071 is classified as an SQL injection vulnerability.
5
Can CVE-2006-7071 be exploited remotely?
Yes, CVE-2006-7071 can be exploited remotely by attackers through the CLIENT_IP parameter.