FrSIRT Advisory : FrSIRT/ADV-2005-0332
CVE Reference : GENERIC-MAP-NOMATCH
Rated as : Moderate
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2005-04-11
* Technical Description *
A new vulnerability was identified in Invision Power Board, which may be exploited by attackers to execute arbitrary SQL commands. The flaw is due to an input validation error in the "memberlist.php" file when handling a specially crafted "st" parameter, which may be exploited by attackers to cause arbitrary SQL commands to be executed.
* Affected Products *
Invision Power Board version 1.3.1 and prior
* Solution *
The FrSIRT is not aware of any official supplied patch for this issue.
* References *
http://www.frsirt.com/english/advisories/2005/0332http://www.hackerscenter.com/archive/view.asp?id=1963 * Credits *
Vulnerability reported by dcrab