Skip to main content

Vendor/product archive

invision_power_services / invision_power_board CVEs

Beta · best-effort

42 CVEs tagged to invision_power_services / invision_power_board1 Critical, 13 High, 26 Medium, 2 Low, 0 Unrated.

CVE-2008-6565

Published Mar 31, 2009

Cross-site scripting (XSS) vulnerability in Invision Power Board 2.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via an IFRAME tag in the signatur…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1359

Published Mar 17, 2008

Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB or IP.Board) 2.3.4 before 2008-03-13 allows remote attackers to inject arbitrary web script or HTML via neste…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0913

Published Feb 22, 2008

Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB or IP.Board) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via crafted BBCodes in an u…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4912

Published Sep 17, 2007

Cross-site scripting (XSS) vulnerability in ips_kernel/class_ajax.php in Invision Power Board (IPB or IP.Board) 2.3.1 up to 20070912 allows remote attackers to inject arbitrary we…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4914

Published Sep 17, 2007

Unspecified vulnerability in the subscriptions manager in Invision Power Board (IPB or IP.Board) 2.3.1 before 20070912 allows remote authenticated users to change the member ID an…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3219

Published Jun 14, 2007

Unspecified vulnerability in sources/action_public/xmlout.php in Invision Power Board (IPB or IP.Board) 2.2.0 through 2.2.2 allows remote attackers to modify another user's profil…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-2963

Published May 31, 2007

Multiple cross-site scripting (XSS) vulnerabilities in Invision Power Board (IPB or IP.Board) 2.2.2, and possibly earlier, allows remote attackers to inject arbitrary web script o…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2349

Published Apr 30, 2007

Cross-site scripting (XSS) vulnerability in Invision Power Board (IP.Board) 2.1.x and 2.2.x allows remote attackers to inject arbitrary web script or HTML by uploading crafted ima…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-7071

Published Mar 2, 2007

SQL injection vulnerability in classes/class_session.php in Invision Power Board (IPB) 2.1 up to 2.1.6 allows remote attackers to execute arbitrary SQL commands via the CLIENT_IP…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-7064

Published Feb 24, 2007

Cross-site scripting (XSS) vulnerability in forum/admin.php for Invision Power Board (IPB) 2.1.6 and earlier allows remote attackers to inject arbitrary web script or HTML as the…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-5203

Published Oct 10, 2006

Invision Power Board (IPB) 2.1.7 and earlier allows remote restricted administrators to inject arbitrary web script or HTML, or execute arbitrary SQL commands, via a forum descrip…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5204

Published Oct 10, 2006

Cross-site scripting (XSS) vulnerability in action_admin/member.php in Invision Power Board (IPB) 2.1.7 and earlier allows remote authenticated users to inject arbitrary web scrip…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-4155

Published Aug 16, 2006

Unspecified vulnerability in func_topic_threaded.php (aka threaded view mode) in Invision Power Board (IPB) before 2.1.7 21013.60810.s allows remote attackers to "access posts out…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3543

Published Jul 13, 2006

Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 1.x and 2.x allow remote attackers to execute arbitrary SQL commands via the (1) idcat and (2) code parameters…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3197

Published Jun 23, 2006

Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.1.6 and earlier allows remote attackers to inject arbitrary web script or HTML via a POST that contains he…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2498

Published May 20, 2006

Invision Power Board (IPB) before 2.1.6 allows remote attackers to execute arbitrary PHP script via attack vectors involving (1) the post_icon variable in classes/post/class_post.…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2204

Published May 5, 2006

SQL injection vulnerability in the topic deletion functionality (post_delete function in func_mod.php) for Invision Power Board 2.1.5 allows remote authenticated moderators to exe…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2217

Published May 5, 2006

SQL injection vulnerability in index.php in Invision Power Board allows remote attackers to execute arbitrary SQL commands via the pid parameter in a reputation action. NOTE: the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2097

Published Apr 29, 2006

SQL injection vulnerability in func_msg.php in Invision Power Board (IPB) 2.1.4 allows remote attackers to execute arbitrary SQL commands via the from_contact field in a private m…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2059

Published Apr 26, 2006

action_public/search.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary PHP code via a search with a crafted value of t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2060

Published Apr 26, 2006

Directory traversal vulnerability in action_admin/paysubscriptions.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote authenticated administrators to…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 42 CVEsPage 1 of 2