vendor:
Invision Power Board
by:
indoushka
7.5
CVSS
HIGH
Backup
N/A
CWE
Product Name: Invision Power Board
Affected Version From: 2.0.4
Affected Version To: 2.0.4
Patch Exists: Yes
Related CWE: N/A
CPE: a:invision_power_services:invision_power_board:2.0.4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux
2009
Invision Power Board(Trial) v2.0.4 Backup Vulnerability
A vulnerability exists in Invision Power Board(Trial) v2.0.4 which allows an attacker to create a backup of the database. This can be done by sending a specially crafted HTTP request to the vulnerable server. The request contains the 'act' parameter set to 'mysql' and the 'code' parameter set to 'dosafebackup' along with the 'create_tbl' parameter set to '1' and the 'addticks' parameter set to '1' and the 'skip' parameter set to '1' and the 'enable_gzip' parameter set to '1'.
Mitigation:
The vendor has released a patch to address this vulnerability.