AlphaOne Technology Support Forums
Welcome, Guest. Please login or register.
December 02, 2008, 12:53:01 PM

Login with username, password and session length
Search:     Advanced search
1733 Posts in 827 Topics by 4756 Members
Latest Member: Uobeley
* Home Help Search Login Register
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Security Announcements  |  Invisionboard  |  Topic: Invisionboard 1.3.1 Vulnerabillity 0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: Invisionboard 1.3.1 Vulnerabillity  (Read 795 times)
AlphaWolf
AOT Administrator
Administrator
Hero Member
*****
Offline Offline

Posts: I am a geek!!



View Profile WWW
Invisionboard 1.3.1 Vulnerabillity
« on: April 11, 2005, 09:36:19 PM »

 FrSIRT Advisory : FrSIRT/ADV-2005-0332
CVE Reference : GENERIC-MAP-NOMATCH
Rated as : Moderate
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2005-04-11

 * Technical Description *

A new vulnerability was identified in Invision Power Board, which may be exploited by attackers to execute arbitrary SQL commands. The flaw is due to an input validation error in the "memberlist.php" file when handling a specially crafted "st" parameter, which may be exploited by attackers to cause arbitrary SQL commands to be executed.

 * Affected Products *

Invision Power Board version 1.3.1 and prior

 * Solution *

The FrSIRT is not aware of any official supplied patch for this issue.

 * References *

http://www.frsirt.com/english/advisories/2005/0332
http://www.hackerscenter.com/archive/view.asp?id=1963

 * Credits *

Vulnerability reported by dcrab
Logged

AlphaOne Tech Webmaster Resources
http://www.alphaone-tech.com/resources/
Pages: [1] Go Up Print 
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Security Announcements  |  Invisionboard  |  Topic: Invisionboard 1.3.1 Vulnerabillity « previous next »
Jump to:  

Powered by MySQL Powered by PHP AlphaOne Technology Support Forums | Powered by SMF 1.0.7.
© 2001-2005, Lewis Media. All Rights Reserved.
Valid XHTML 1.0! Valid CSS!