IP.Board Multiple Vulnerabilities
Invision Power Board (IPB) is a professional forum system that has been built from the ground up with speed and security in mind. It is used by a great many people all over the world. All versions of Invision Power Board are vulnerable to a serious SQL Injection vulnerability. An attacker does not have to be logged in, or even have access or permission to view the forums in order to exploit this vulnerability. It is possible for an attacker to conduct Cross Site Scripting attacks in all versions of invision power board prior to the recently released 2.0.4. This vulnerability exists due to data submitted to the 'highlite' parameter not being sanatized properly when displaying search results. The same issue also exists in 'sources/topics.php'. The only condition is that the data sent to the 'highlite' parameter must be double hex encoded data in order to bypass the global sanatation methods. I have discovered a serious SQL Injection issue in Invision Power Board that affects most all versions of Invision Power Board regardless of most server configurations.