CVE-2007-2349
- EPSS 0.35%
- Published 30.04.2007 22:19:00
- Last modified 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in Invision Power Board (IP.Board) 2.1.x and 2.2.x allows remote attackers to inject arbitrary web script or HTML by uploading crafted images or PDF files.
CVE-2006-7071
- EPSS 1.46%
- Published 02.03.2007 21:18:00
- Last modified 09.04.2025 00:30:58
SQL injection vulnerability in classes/class_session.php in Invision Power Board (IPB) 2.1 up to 2.1.6 allows remote attackers to execute arbitrary SQL commands via the CLIENT_IP parameter.
CVE-2006-7064
- EPSS 0.57%
- Published 24.02.2007 01:28:00
- Last modified 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in forum/admin.php for Invision Power Board (IPB) 2.1.6 and earlier allows remote attackers to inject arbitrary web script or HTML as the administrator via the phpinfo parameter.
CVE-2006-5204
- EPSS 0.48%
- Published 10.10.2006 04:06:00
- Last modified 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in action_admin/member.php in Invision Power Board (IPB) 2.1.7 and earlier allows remote authenticated users to inject arbitrary web script or HTML via a reference to a script in the avatar setting, which can ...
CVE-2006-5203
- EPSS 0.31%
- Published 10.10.2006 04:06:00
- Last modified 09.04.2025 00:30:58
Invision Power Board (IPB) 2.1.7 and earlier allows remote restricted administrators to inject arbitrary web script or HTML, or execute arbitrary SQL commands, via a forum description that contains a crafted image with PHP code, which is executed whe...
CVE-2006-4155
- EPSS 0.56%
- Published 16.08.2006 22:04:00
- Last modified 03.04.2025 01:03:51
Unspecified vulnerability in func_topic_threaded.php (aka threaded view mode) in Invision Power Board (IPB) before 2.1.7 21013.60810.s allows remote attackers to "access posts outside the topic."
CVE-2006-3543
- EPSS 0.57%
- Published 13.07.2006 00:05:00
- Last modified 03.04.2025 01:03:51
Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 1.x and 2.x allow remote attackers to execute arbitrary SQL commands via the (1) idcat and (2) code parameters in a ketqua action in index.php; the id parameter in a (3) Attach and ...
CVE-2006-3197
- EPSS 0.45%
- Published 23.06.2006 00:02:00
- Last modified 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.1.6 and earlier allows remote attackers to inject arbitrary web script or HTML via a POST that contains hexadecimal-encoded HTML.
CVE-2006-2498
- EPSS 0.78%
- Published 20.05.2006 03:02:00
- Last modified 03.04.2025 01:03:51
Invision Power Board (IPB) before 2.1.6 allows remote attackers to execute arbitrary PHP script via attack vectors involving (1) the post_icon variable in classes/post/class_post.php and (2) the df value in action_public/moderate.php.
CVE-2006-2217
- EPSS 0.26%
- Published 05.05.2006 12:46:00
- Last modified 03.04.2025 01:03:51
SQL injection vulnerability in index.php in Invision Power Board allows remote attackers to execute arbitrary SQL commands via the pid parameter in a reputation action. NOTE: the provenance of this information is unknown; the details are obtained so...