First published: Tue Mar 20 2018(Updated: )
SQL injection vulnerability in Invision Power Board (aka IPB or IP.Board) before 3.4.6 allows remote attackers to execute arbitrary SQL commands via the cId parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Invisioncommunity Invision Power Board | <3.4.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4928 is a SQL injection vulnerability in Invision Power Board (aka IPB or IP.Board) before version 3.4.6.
CVE-2014-4928 has a severity score of 8.8, which is considered high.
Remote attackers can exploit CVE-2014-4928 by executing arbitrary SQL commands via the cId parameter.
The affected software by CVE-2014-4928 is Invision Power Board (aka IPB or IP.Board) before version 3.4.6.
Yes, the fix for CVE-2014-4928 is to update Invision Power Board to version 3.4.6 or higher.