CVE Vulnerabilities

CVE-2006-2061

Published: Apr 26, 2006 | Modified: Oct 18, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

SQL injection vulnerability in lib/func_taskmanager.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary SQL commands via the ck parameter, which can inject at most 32 characters.

Affected Software

Name Vendor Start Version End Version
Invision_board Invision_power_services 2.0 (including) 2.0 (including)
Invision_board Invision_power_services 2.0.1 (including) 2.0.1 (including)
Invision_board Invision_power_services 2.0.2 (including) 2.0.2 (including)
Invision_board Invision_power_services 2.0.3 (including) 2.0.3 (including)
Invision_board Invision_power_services 2.0.4 (including) 2.0.4 (including)
Invision_board Invision_power_services 2.0_alpha_3 (including) 2.0_alpha_3 (including)
Invision_board Invision_power_services 2.0_pdr3 (including) 2.0_pdr3 (including)
Invision_board Invision_power_services 2.0_pf1 (including) 2.0_pf1 (including)
Invision_board Invision_power_services 2.0_pf2 (including) 2.0_pf2 (including)
Invision_board Invision_power_services 2.1 (including) 2.1 (including)
Invision_board Invision_power_services 2.1.5 (including) 2.1.5 (including)
Invision_board Invision_power_services 2.1_alpha2 (including) 2.1_alpha2 (including)
Invision_power_board Invision_power_services 2.1.5_2006-03-08 (including) 2.1.5_2006-03-08 (including)

References