7.5
CVSSv2

CVE-2005-1598

Published: 16/05/2005 Updated: 19/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 765
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in Invision Power Board (IPB) 2.0.3 and previous versions allows remote malicious users to execute arbitrary SQL commands via a crafted cookie password hash (pass_hash) that modifies the internal $pid variable.

Vulnerable Product Search on Vulmon Subscribe to Product

invision power services invision board 2.0_alpha_3

invision power services invision board 2.0_pdr3

invision power services invision power board 2.0.3

invision power services invision board 1.1.1

invision power services invision board 1.1.2

invision power services invision board 1.2

invision power services invision board 1.3

invision power services invision board 1.0

invision power services invision board 1.0.1

Exploits

# danica jones <danica6699@gmailcom> Tutorial for the recent exploit released by Petey Beege 1 Get the exploit from wwwmilw0rmcom/idphp?id=1013 (wwwexploit-dbcom/exploits/1013/) 2 Make sure you have LWP::UserAgent perl module if not do this: a perl -MCPAN -e 'shell' b inside the perl shell, do this 'insta ...
#!/usr/bin/perl -w ################################################################## # This one actually works :) Just paste the outputted cookie into # your request header using livehttpheaders or something and you # will probably be logged in as that user No need to decrypt it! # Exploit coded by "Tony Little Lately" and "Petey Beege" ######### ...
IPBoard Multiple Vulnerabilities Vendor: Invision Power Services Product: IPBoard Version: <= 203 Website: wwwinvisionboardcom/ BID: 13529 13534 CVE: CVE-2005-1597 CVE-2005-1598 OSVDB: 16297 16298 SECUNIA: 15265 PACKETSTORM: 39098 Description: Invision Power Board (IPB) is a professional forum system that has been built from ...