CVE-2014-9239
03.12.2014, 21:59
SQL injection vulnerability in the IPS Connect service (interface/ipsconnect/ipsconnect.php) in Invision Power Board (aka IPB or IP.Board) 3.3.x and 3.4.x through 3.4.7 before 20141114 allows remote attackers to execute arbitrary SQL commands via the id[] parameter.
Vendor | Product | Version |
---|---|---|
invisioncommunity | invision_power_board | 3.3.0 |
invisioncommunity | invision_power_board | 3.3.0:alpha1 |
invisioncommunity | invision_power_board | 3.3.0:alpha2 |
invisioncommunity | invision_power_board | 3.3.0:beta1 |
invisioncommunity | invision_power_board | 3.3.0:beta2 |
invisioncommunity | invision_power_board | 3.3.0:beta3 |
invisioncommunity | invision_power_board | 3.3.0:beta4 |
invisioncommunity | invision_power_board | 3.3.1 |
invisioncommunity | invision_power_board | 3.3.2 |
invisioncommunity | invision_power_board | 3.3.3 |
invisioncommunity | invision_power_board | 3.3.4 |
invisioncommunity | invision_power_board | 3.4.0 |
invisioncommunity | invision_power_board | 3.4.0:alpha1 |
invisioncommunity | invision_power_board | 3.4.0:beta1 |
invisioncommunity | invision_power_board | 3.4.0:beta2 |
invisioncommunity | invision_power_board | 3.4.0:beta3 |
invisioncommunity | invision_power_board | 3.4.0:beta4 |
invisioncommunity | invision_power_board | 3.4.0:beta5 |
invisioncommunity | invision_power_board | 3.4.1 |
invisioncommunity | invision_power_board | 3.4.2 |
invisioncommunity | invision_power_board | 3.4.3 |
invisioncommunity | invision_power_board | 3.4.4 |
invisioncommunity | invision_power_board | 3.4.5 |
invisioncommunity | invision_power_board | 3.4.6 |
invisionpower | invision_power_board | 3.4.7 |
𝑥
= Vulnerable software versions
References