Vulnerability index

Browse CVEs

52 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Invision Power Board HIGH 7.5
CVE-2006-1076

SQL injection vulnerability in index.php, possibly during a showtopic operation, in Invision Power Board (IPB) 2.1.5 allows remote attackers to execu…

No fix yet
Fix from $1,950 2006-03-09
Invision Power Board MEDIUM 5.0
CVE-2006-0909

Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to view sensitive information via a direct request to multiple PHP scripts that …

Mitigation only
Fix from $1,600 2006-02-28
Invision Power Board MEDIUM 5.0
CVE-2006-0910

Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to list directory contents via a direct request to multiple directories, includi…

Mitigation only
Fix from $1,600 2006-02-28
Invision Board MEDIUM 6.5
CVE-2005-3549

Direct code injection vulnerability in Task Manager in Invision Power Board 2.0.1 allows limited remote attackers to execute arbitrary code by refere…

Patch available
Fix from $1,600 2005-11-16
Invision Gallery HIGH 7.5
CVE-2005-3395

SQL injection vulnerability in Invision Gallery 2.0.3 allows remote attackers to execute arbitrary SQL commands via the st parameter.

Patch available
Fix from $1,950 2005-11-01
Invision Board MEDIUM 5.0
CVE-2005-2542

Invision Power Board (IPB) 1.0.3 allows remote attackers to inject arbitrary web script or HTML via an attachment, which is automatically downloaded …

No fix yet
Fix from $1,600 2005-08-10
Invision Community Blog HIGH 7.5
CVE-2005-1946

Multiple SQL injection vulnerabilities in Invision Blog before 1.1.2 Final allow remote attackers to execute arbitrary SQL commands via the (1) eid p…

Patch available
Fix from $1,950 2005-06-09
Invision Gallery HIGH 7.5
CVE-2005-1948

Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL commands via (1) the comment …

Patch available
Fix from $1,950 2005-06-09
Invision Board MEDIUM 5.0
CVE-2005-1817

Invision Power Board (IPB) 1.0 through 1.3 allows remote attackers to edit arbitrary forum posts via a direct request to index.php with modified para…

No fix yet
Fix from $1,600 2005-06-01
Invision Board HIGH 7.5
CVE-2005-1598EPSS 14%

SQL injection vulnerability in Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via a crafted c…

Patch available
Fix from $1,950 2005-05-16
Invision Community Blog HIGH 7.5
CVE-2005-0217

SQL injection vulnerability in index.php in Invision Community Blog allows remote attackers to execute arbitrary SQL commands via the eid parameter.

Mitigation only
Fix from $1,950 2005-05-02
Invision Board HIGH 7.5
CVE-2005-1070

SQL injection vulnerability in index.php in Invision Power Board 1.3.1 Final and earlier allows remote attackers to execute arbitrary SQL commands vi…

Mitigation only
Fix from $1,950 2005-04-11
Invision Board HIGH 7.5
CVE-2004-1531

SQL injection vulnerability in post.php in Invision Power Board (IPB) 2.0.0 through 2.0.2 allows remote attackers to execute arbitrary SQL commands v…

Patch available
Fix from $1,950 2004-12-31
Invision Gallery HIGH 7.5
CVE-2004-1835

Multiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote attackers to execute arbitrary SQL via the (1) img, (2) ca…

No fix yet
Fix from $1,950 2004-12-31
Invision Power Top Site List HIGH 7.5
CVE-2004-1836

SQL injection vulnerability in index.php in Invision Power Top Site List 1.1 RC 2 and earlier allows remote attackers to execute arbitrary SQL via th…

No fix yet
Fix from $1,950 2004-12-31
Invision Board HIGH 10.0
CVE-2004-0338

SQL injection vulnerability in search.php for Invision Board Forum allows remote attackers to execute arbitrary SQL queries via the st parameter.

Mitigation only
Fix from $1,950 2004-11-23
Invision Board MEDIUM 6.8
CVE-2004-0359EPSS 6%

Cross-site scripting (XSS) vulnerability in index.php for Invision Power Board 1.3 final allows remote attackers to execute arbitrary script as other…

No fix yet
Fix from $1,600 2004-11-23
Invision Board MEDIUM 5.0
CVE-2004-0355

Invision Power Board 1.3 Final allows remote attackers to gain sensitive information by selecting a file for "Personal Photo" that is not an image fi…

Mitigation only
Fix from $1,600 2004-11-23
Invision Board HIGH 7.5
CVE-2004-1785

SQL injection vulnerability in calendar.php for Invision Power Board 1.3 allows remote attackers to execute arbitrary SQL commands via the m paramete…

Patch available
Fix from $1,950 2004-01-03
Invision Power Board MEDIUM 6.8
CVE-2003-1385

ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root…

No fix yet
Fix from $1,600 2003-12-31
Invision Board MEDIUM 5.0
CVE-2003-1454

Invision Power Services Invision Board 1.0 through 1.1.1, when a forum is password protected, stores the administrator password in a cookie in plaint…

Mitigation only
Fix from $1,600 2003-12-31
Invision Board MEDIUM 5.0
CVE-2002-1149

The installation procedure for Invision Board suggests that users install the phpinfo.php program under the web root, which leaks sensitive informati…

Mitigation only
Fix from $1,600 2002-10-11