7.5
CVSSv2

CVE-2009-3974

Published: 18/11/2009 Updated: 03/06/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Invision Power Board (IPB or IP.Board) 3.0.0, 3.0.1, and 3.0.2 allow remote malicious users to execute arbitrary SQL commands via the (1) search_term parameter to admin/applications/core/modules_public/search/search.php and (2) aid parameter to admin/applications/core/modules_public/global/lostpass.php. NOTE: on 20090818, the vendor patched 3.0.2 without changing the version number.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

invisioncommunity invision power board 3.0.2

invisioncommunity invision power board 3.0.0

invisioncommunity invision power board 3.0.1