CVE Database
/

CVE-2006-3544

Back to search

CVE-2006-3544

Published: Jul 13, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 1.3 Final allow remote attackers to execute arbitrary SQL commands via the CODE parameter in a (1) Stats, (2) Mail, and (3) Reg action in index.php. NOTE: the developer has disputed this issue, stating that "At no point does the CODE parameter touch the database. The CODE parameter is used in a SWITCH statement to determine which function to run.

VendorProductVersions

n/a

n/a

affected
n/a

References

1225
third-party-advisory
x_refsource_SREASON
18782
vdb-entry
x_refsource_BID
30084
vdb-entry
x_refsource_OSVDB
ipb-index-sql-injection(27555)
vdb-entry
x_refsource_XF

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now