7.5
CVSSv2

CVE-2005-1070

Published: 11/04/2005 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in index.php in Invision Power Board 1.3.1 Final and previous versions allows remote malicious users to execute arbitrary SQL commands via the st parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

invision power services invision board 1.3

invision power services invision board 1.3.1_final

invision power services invision board 1.0

invision power services invision board 1.0.1

invision power services invision board 1.3_final

invision power services invision board 1.1.1

invision power services invision board 1.1.2

invision power services invision board 1.2

Exploits

source: wwwsecurityfocuscom/bid/13097/info Invision Power Board is reported prone to an SQL injection vulnerability Due to improper filtering of user-supplied data, attackers may pass SQL statements to the underlying database through the 'st' parameter Invision Power Board 131 and prior versions are affected by this issue w ...