PT-2005-2784 · Invision · Invision Power Board

Publicado

2005-06-01

·

Atualizado

2008-09-05

·

CVE-2005-1817

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Invision Power Board (IPB) versions 1.0 through 1.3
Description The issue allows remote attackers to edit arbitrary forum posts. This is achieved by sending a direct request to "index.php" with modified parameters.
Recommendations For Invision Power Board (IPB) versions 1.0 through 1.3, consider restricting access to the "index.php" endpoint until a patch is available. As a temporary workaround, avoid using modified parameters in requests to "index.php" to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-1817

Produtos afetados

Invision Power Board