CVE-2012-2226: Malicious File Upload
Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute arbitrary code by uploading a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2012-2226.
What is the severity of CVE-2012-2226?
The severity of CVE-2012-2226 is critical (9.8).
What is the affected software?
The affected software is Invision Power Board before 3.3.1.
How does CVE-2012-2226 impact the affected software?
CVE-2012-2226 allows remote attackers to obtain sensitive information or execute arbitrary code by uploading a malicious file.
Are there any references available for CVE-2012-2226?
Yes, there are references available for CVE-2012-2226. You can find them at the following links: [http://www.securityfocus.com/bid/52998](http://www.securityfocus.com/bid/52998) and [https://exchange.xforce.ibmcloud.com/vulnerabilities/74855](https://exchange.xforce.ibmcloud.com/vulnerabilities/74855)