Vulnerability index

Browse CVEs

52 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Invision Power Board HIGH 7.5
CVE-2008-4171

SQL injection vulnerability in xmlout.php in Invision Power Board (IP.Board or IPB) 2.2.x and 2.3.x allows remote attackers to execute arbitrary SQL …

Patch available
Fix from $1,950 2008-09-22
Invision Gallery HIGH 7.5
CVE-2008-0421

SQL injection vulnerability in Invision Gallery 2.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the album parameter i…

Fix: after 2.0.7
Fix from $1,950 2008-01-23
Invision Power Board HIGH 7.5
CVE-2007-5688

Multiple SQL injection vulnerabilities in directory.php in the Multi-Forums (aka Multi Host Forum Pro) module 1.3.3, for phpBB and Invision Power Boa…

No fix yet
Fix from $1,950 2007-10-29
Invision Power Board HIGH 7.5
CVE-2007-4913

ips_kernel/class_upload.php in Invision Power Board (IPB or IP.Board) 2.3.1 up to 20070912 allows remote attackers to upload arbitrary script files w…

Fix: after 2.3.1
Fix from $1,950 2007-09-17
Invision Power Board MEDIUM 6.0
CVE-2007-4914

Unspecified vulnerability in the subscriptions manager in Invision Power Board (IPB or IP.Board) 2.3.1 before 20070912 allows remote authenticated us…

Fix: after 2.3.1
Fix from $1,600 2007-09-17
Invision Power Board HIGH 7.8
CVE-2007-3219

Unspecified vulnerability in sources/action_public/xmlout.php in Invision Power Board (IPB or IP.Board) 2.2.0 through 2.2.2 allows remote attackers t…

Patch available
Fix from $1,950 2007-06-14
Invision Power Board MEDIUM 5.8
CVE-2007-2349

Cross-site scripting (XSS) vulnerability in Invision Power Board (IP.Board) 2.1.x and 2.2.x allows remote attackers to inject arbitrary web script or…

Patch available
Fix from $1,600 2007-04-30
Invision Power Board HIGH 7.5
CVE-2006-7071

SQL injection vulnerability in classes/class_session.php in Invision Power Board (IPB) 2.1 up to 2.1.6 allows remote attackers to execute arbitrary S…

Patch available
Fix from $1,950 2007-03-02
Invision Power Board HIGH 9.3
CVE-2006-7064

Cross-site scripting (XSS) vulnerability in forum/admin.php for Invision Power Board (IPB) 2.1.6 and earlier allows remote attackers to inject arbitr…

Mitigation only
Fix from $1,950 2007-02-24
Invision Community Blog HIGH 7.5
CVE-2006-6369

SQL injection vulnerability in lib/entry_reply_entry.php in Invision Community Blog Mod 1.2.4 allows remote attackers to execute arbitrary SQL comman…

Patch available
Fix from $1,950 2006-12-07
Invision Gallery HIGH 7.5
CVE-2006-6370

SQL injection vulnerability in forum/modules/gallery/post.php in Invision Gallery 2.0.7 allows remote attackers to cause a denial of service and poss…

Mitigation only
Fix from $1,950 2006-12-07
Invision Gallery HIGH 7.5
CVE-2006-5206

SQL injection vulnerability in Invision Gallery 2.0.7 allows remote attackers to execute arbitrary SQL commands via the album parameter in (1) index.…

Fix: after 2.0.7
Fix from $1,950 2006-10-10
Invision Power Board MEDIUM 5.1
CVE-2006-5203

Invision Power Board (IPB) 2.1.7 and earlier allows remote restricted administrators to inject arbitrary web script or HTML, or execute arbitrary SQL…

Fix: after 2.1.7
Fix from $1,600 2006-10-10
Invision Gallery MEDIUM 5.0
CVE-2006-5205EPSS 11%

Directory traversal vulnerability in Invision Gallery 2.0.7 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the dir pa…

No fix yet
Fix from $1,600 2006-10-10
Invision Power Board HIGH 7.5
CVE-2006-4155

Unspecified vulnerability in func_topic_threaded.php (aka threaded view mode) in Invision Power Board (IPB) before 2.1.7 21013.60810.s allows remote …

Fix: after 2.1.7
Fix from $1,950 2006-08-16
Invision Power Board HIGH 7.5
CVE-2006-3543

Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 1.x and 2.x allow remote attackers to execute arbitrary SQL commands via the (1)…

No fix yet
Fix from $1,950 2006-07-13
Invision Board HIGH 7.5
CVE-2006-3544

Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 1.3 Final allow remote attackers to execute arbitrary SQL commands via the CODE …

No fix yet
Fix from $1,950 2006-07-13
Invision Power Board MEDIUM 6.4
CVE-2006-2498

Invision Power Board (IPB) before 2.1.6 allows remote attackers to execute arbitrary PHP script via attack vectors involving (1) the post_icon variab…

Patch available
Fix from $1,600 2006-05-20
Invision Community Blog MEDIUM 6.4
CVE-2006-2251

SQL injection vulnerability in the do_mmod function in mod.php in Invision Community Blog (ICB) 1.1.2 final through 1.2 allows remote attackers with …

Patch available
Fix from $1,600 2006-05-09
Invision Power Board HIGH 7.5
CVE-2006-2217

SQL injection vulnerability in index.php in Invision Power Board allows remote attackers to execute arbitrary SQL commands via the pid parameter in a…

Mitigation only
Fix from $1,950 2006-05-05
Invision Power Board MEDIUM 5.5
CVE-2006-2204

SQL injection vulnerability in the topic deletion functionality (post_delete function in func_mod.php) for Invision Power Board 2.1.5 allows remote a…

Patch available
Fix from $1,600 2006-05-05
Invision Gallery MEDIUM 6.4
CVE-2006-2202

SQL injection vulnerability in post.php in Invision Gallery 2.0.6 allows remote attackers to execute arbitrary SQL commands via the album parameter.

Patch available
Fix from $1,600 2006-05-04
Invision Power Board HIGH 7.5
CVE-2006-2097

SQL injection vulnerability in func_msg.php in Invision Power Board (IPB) 2.1.4 allows remote attackers to execute arbitrary SQL commands via the fro…

Fix: after 2.1.4
Fix from $1,950 2006-04-29
Invision Power Board MEDIUM 6.4
CVE-2006-2060

Directory traversal vulnerability in action_admin/paysubscriptions.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote au…

Patch available
Fix from $1,600 2006-04-26
Invision Power Board MEDIUM 5.0
CVE-2006-2059EPSS 8%

action_public/search.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary PHP code via a se…

Patch available
Fix from $1,600 2006-04-26
Invision Board MEDIUM 5.0
CVE-2006-2061

SQL injection vulnerability in lib/func_taskmanager.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to exec…

Patch available
Fix from $1,600 2006-04-26
Invision Power Board MEDIUM 6.8
CVE-2006-1369

Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.1.5 and earlier before 20060308 allows remote attackers to inject arbitrary …

Mitigation only
Fix from $1,600 2006-03-23
Invision Power Board HIGH 7.5
CVE-2006-1288

Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 2.0.4 and 2.1.4 before 20060105 allow remote attackers to execute arbitrary SQL …

Patch available
Fix from $1,950 2006-03-19
Invision Power Board MEDIUM 5.8
CVE-2006-1287

Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.0.4 and 2.1.4 before 20060130 allows remote attackers to steal cookies and p…

Patch available
Fix from $1,600 2006-03-19
Invision Power Board MEDIUM 5.1
CVE-2006-1267

Invision Power Board 2.1.4 allows remote attackers to hijack sessions and possibly gain administrative privileges by obtaining the session ID from th…

No fix yet
Fix from $1,600 2006-03-19