CVE-2014-4928: SQL Injection
Published Mar 20, 2018
·Updated
SQL injection vulnerability in Invision Power Board (aka IPB or IP.Board) before 3.4.6 allows remote attackers to execute arbitrary SQL commands via the cId parameter.
Affected Software
1 affected component
Invisioncommunity Invision Power Board<3.4.6
Event History
Mar 20, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is CVE-2014-4928?
CVE-2014-4928 is a SQL injection vulnerability in Invision Power Board (aka IPB or IP.Board) before version 3.4.6.
2
How severe is the CVE-2014-4928 vulnerability?
CVE-2014-4928 has a severity score of 8.8, which is considered high.
3
How can remote attackers exploit CVE-2014-4928?
Remote attackers can exploit CVE-2014-4928 by executing arbitrary SQL commands via the cId parameter.
4
What is the affected software by CVE-2014-4928?
The affected software by CVE-2014-4928 is Invision Power Board (aka IPB or IP.Board) before version 3.4.6.
5
Is there a fix available for CVE-2014-4928?
Yes, the fix for CVE-2014-4928 is to update Invision Power Board to version 3.4.6 or higher.