CVE-2014-9239

SQL injection vulnerability in the IPS Connect service (interface/ipsconnect/ipsconnect.php) in Invision Power Board (aka IPB or IP.Board) 3.3.x and 3.4.x through 3.4.7 before 20141114 allows remote attackers to execute arbitrary SQL commands via the id[] parameter.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
VendorProductVersion
invisioncommunityinvision_power_board
3.3.0
invisioncommunityinvision_power_board
3.3.0:alpha1
invisioncommunityinvision_power_board
3.3.0:alpha2
invisioncommunityinvision_power_board
3.3.0:beta1
invisioncommunityinvision_power_board
3.3.0:beta2
invisioncommunityinvision_power_board
3.3.0:beta3
invisioncommunityinvision_power_board
3.3.0:beta4
invisioncommunityinvision_power_board
3.3.1
invisioncommunityinvision_power_board
3.3.2
invisioncommunityinvision_power_board
3.3.3
invisioncommunityinvision_power_board
3.3.4
invisioncommunityinvision_power_board
3.4.0
invisioncommunityinvision_power_board
3.4.0:alpha1
invisioncommunityinvision_power_board
3.4.0:beta1
invisioncommunityinvision_power_board
3.4.0:beta2
invisioncommunityinvision_power_board
3.4.0:beta3
invisioncommunityinvision_power_board
3.4.0:beta4
invisioncommunityinvision_power_board
3.4.0:beta5
invisioncommunityinvision_power_board
3.4.1
invisioncommunityinvision_power_board
3.4.2
invisioncommunityinvision_power_board
3.4.3
invisioncommunityinvision_power_board
3.4.4
invisioncommunityinvision_power_board
3.4.5
invisioncommunityinvision_power_board
3.4.6
invisionpowerinvision_power_board
3.4.7
𝑥
= Vulnerable software versions