First published: Tue Jul 12 2016(Updated: )
applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.1.13, when used with PHP before 5.4.24 or 5.5.x before 5.5.8, allows remote attackers to execute arbitrary code via the content_class parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Invisioncommunity Invision Power Board | <=4.1.12.3 | |
PHP PHP | <=5.4.23 | |
PHP PHP | =5.5.0 | |
PHP PHP | =5.5.0-alpha1 | |
PHP PHP | =5.5.0-alpha2 | |
PHP PHP | =5.5.0-alpha3 | |
PHP PHP | =5.5.0-alpha4 | |
PHP PHP | =5.5.0-alpha5 | |
PHP PHP | =5.5.0-alpha6 | |
PHP PHP | =5.5.0-beta1 | |
PHP PHP | =5.5.0-beta2 | |
PHP PHP | =5.5.0-beta3 | |
PHP PHP | =5.5.0-beta4 | |
PHP PHP | =5.5.0-rc1 | |
PHP PHP | =5.5.0-rc2 | |
PHP PHP | =5.5.1 | |
PHP PHP | =5.5.2 | |
PHP PHP | =5.5.3 | |
PHP PHP | =5.5.4 | |
PHP PHP | =5.5.5 | |
PHP PHP | =5.5.6 | |
PHP PHP | =5.5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.