vendor:
Invision Power Board Army System Mod
by:
Alex & fRoGGz
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Invision Power Board Army System Mod
Affected Version From: 2.1.2000
Affected Version To: 2.1.2000
Patch Exists: YES
Related CWE: N/A
CPE: a:invision_power_services:invision_power_board_army_system_mod:2.1.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Latest version (2.1.0)
2006
Invision Power Board Army System Mod 2.1 SQL Injection Exploit
This exploit allows an attacker to inject malicious SQL queries into the Invision Power Board Army System Mod 2.1. The query of the SQL Injection depends on the number of fields in the SQL table. The exploit has been tested on a new fresh IPB 2.1.x with Army System Mod 2.1 installed.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in SQL queries.