5.5
CVSSv2

CVE-2006-2204

Published: 05/05/2006 Updated: 18/10/2018
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N

Vulnerability Summary

SQL injection vulnerability in the topic deletion functionality (post_delete function in func_mod.php) for Invision Power Board 2.1.5 allows remote authenticated moderators to execute arbitrary SQL commands via the selectedpids parameter, which bypasses an integer value check when the $id variable is an array.

Vulnerable Product Search on Vulmon Subscribe to Product

invision power services invision power board 2.0.x

invision power services invision power board 2.1

invision power services invision power board 2.1_alpha2

invision power services invision power board 2.1_beta2

invision power services invision power board 2.1_beta3

invision power services invision power board 2.0.1

invision power services invision power board 2.0.2

invision power services invision power board 2.1.2

invision power services invision power board 2.1.3

invision power services invision power board 2.1_rc1

invision power services invision power board 2.0.3

invision power services invision power board 2.0.4

invision power services invision power board 2.1.4

invision power services invision power board 2.1.5

invision power services invision power board 2.0.0

invision power services invision power board 2.1.0

invision power services invision power board 2.1.1

invision power services invision power board 2.1_beta4

invision power services invision power board 2.1_beta5