Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> CGI abuses >> Invision Power Board Post SQL Injection Vulnerability


Vulnerability Assessment Details

Invision Power Board Post SQL Injection Vulnerability

Vulnerability Assessment Summary
Detect Invision Power Board Post SQL Injection

Detailed Explanation for this Vulnerability Assessment

Summary :

The remote web server contains a PHP application that is vulnerable to
a SQL injection attack.

Description :

The version of Invision Power Board on the remote host suffers from a
flaw in 'sources/post.php' that permits injection of SQL commands into
the remote SQL database. A possible hacker may use this flaw to gain
control of the remote database and possibly to overwrite files on the
remote host.

See also :

http://archives.neohapsis.com/archives/bugtraq/2004-11/0233.html
http://forums.invisionpower.com/index.php?showtopic=154916

Solution :

Replace the 'sources/post.php' file with the one referenced in the
vendor advisory above.

Network Security Threat Level:

Medium / CVSS Base Score : 5
(AV:R/AC:L/Au:NR/C:P/A:N/I:P/B:N)

Networks Security ID: 11703

Vulnerability Assessment Copyright: This script is Copyright (C) 2004-2006 Tenable Network Security

Cables, Connectors


Samsung Galaxy Tab A8 10.5

Samsung Galaxy Tab A8 10.5" SM-X200 128GB Wifi Only Tablet Open Box

$149.99



Genuine Samsung Book Cover Keyboard for 14.6

Genuine Samsung Book Cover Keyboard for 14.6" Galaxy Tab S8 Ultra | S8 Ultra 5G

$89.99



Samsung - S Pen Creator Edition - White picture

Samsung - S Pen Creator Edition - White

$40.00



Samsung Galaxy Tab A9 (X110) 64GB 4GB RAM International Version (New) picture

Samsung Galaxy Tab A9 (X110) 64GB 4GB RAM International Version (New)

$129.99



Samsung Galaxy 12.4 Inch Slim Keyboard For S7+ | S7 FE | S8+ | S8+ 5G EF-DT730 picture

Samsung Galaxy 12.4 Inch Slim Keyboard For S7+ | S7 FE | S8+ | S8+ 5G EF-DT730

$49.99



SAMSUNG AM-P613NZBMXAR Galaxy S6 Lite 2022 10.4

SAMSUNG AM-P613NZBMXAR Galaxy S6 Lite 2022 10.4" 64GB Wi-Fi Tablet With S Pen,

$134.00



Samsung USB 3.1 Flash Drive Bar Plus 256gb TITAN Gray picture

Samsung USB 3.1 Flash Drive Bar Plus 256gb TITAN Gray

$24.10



Samsung Galaxy Tab E 8

Samsung Galaxy Tab E 8" 16GB Black SM-T377V (Verizon) Android Tablet IG1000

$30.35



Dell Y7D7D Samsung PM1735 1.6TB PCIe 4.0 x8 NVMe HHHL SSD MZ-PLJ1T60 picture

Dell Y7D7D Samsung PM1735 1.6TB PCIe 4.0 x8 NVMe HHHL SSD MZ-PLJ1T60

$249.99



SAMSUNG  24

SAMSUNG 24" Monitor Full HD LED/LCD - GRADE A CONDITION - S24E650PL

$69.95



Discussions

No Discussions have been posted on this vulnerability.