CVE Vulnerabilities

CVE-2006-2251

Published: May 09, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

SQL injection vulnerability in the do_mmod function in mod.php in Invision Community Blog (ICB) 1.1.2 final through 1.2 allows remote attackers with moderator privileges to execute arbitrary SQL commands via the selectedbids parameter.

Affected Software

NameVendorStart VersionEnd Version
Invision_community_blogInvision_power_services1.0 (including)1.0 (including)
Invision_community_blogInvision_power_services1.1 (including)1.1 (including)
Invision_community_blogInvision_power_services1.1.2_final (including)1.1.2_final (including)
Invision_community_blogInvision_power_services1.2 (including)1.2 (including)

References