CVE-2008-4171: SQL Injection
Published Sep 22, 2008
·Updated
SQL injection vulnerability in xmlout.php in Invision Power Board (IP.Board or IPB) 2.2.x and 2.3.x allows remote attackers to execute arbitrary SQL commands via the name parameter.
Affected Software
2 affected components
Invision Power Services Invision Power Board=2.2
Invision Power Services Invision Power Board=2.3
Remediation
Patch Available
Event History
Sep 22, 2008
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-4171?
CVE-2008-4171 is rated as a high severity vulnerability due to its potential for remote SQL command execution.
2
How do I fix CVE-2008-4171?
To fix CVE-2008-4171, ensure that you are running an updated version of Invision Power Board that is not affected by the vulnerability.
3
What versions are affected by CVE-2008-4171?
CVE-2008-4171 affects Invision Power Board versions 2.2.x and 2.3.x.
4
What type of vulnerability is CVE-2008-4171?
CVE-2008-4171 is an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
5
What could happen if CVE-2008-4171 is exploited?
If exploited, CVE-2008-4171 could allow attackers to manipulate the database, potentially leading to data theft or loss.