7.5
CVSSv2

CVE-2004-1836

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in index.php in Invision Power Top Site List 1.1 RC 2 and previous versions allows remote malicious users to execute arbitrary SQL via the id parameter of the comments action.

Vulnerable Product Search on Vulmon Subscribe to Product

invision power services invision power top site list 1.1_rc2

invision power services invision power top site list 1.0

invision power services invision power top site list 1.1

Exploits

source: wwwsecurityfocuscom/bid/9945/info It has been reported that Top Site List may be prone to an SQL injection vulnerability that may allow remote attackers to pass malicious input to database queries, resulting in modification of query logic or other attacks The issue exists due to insufficient sanitizing of the 'id' URI parameter w ...