7.5
CVSSv2

CVE-2006-6369

Published: 07/12/2006 Updated: 17/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in lib/entry_reply_entry.php in Invision Community Blog Mod 1.2.4 allows remote malicious users to execute arbitrary SQL commands via the eid parameter, when accessed through the "Preview message" functionality.

Vulnerable Product Search on Vulmon Subscribe to Product

invision power services invision community blog 1.2.4

Exploits

1 Open any blog entry 2 Try to reply to any message 3 Push "Preview message" button (Do not post your reply) 4 Save source code of opened page to your PC 5 Find this string <input type='hidden' name='eid' value='<BLOG_ENTRY_ID>' /> 6 Change <BLOG_ENTRY_ID> with this SQL Injection: <BLOG_ENTRY_ID> UNION SELECT bentr ...