Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Secthrowaway

#35430of 53,624
7.5Total CVSS
Vulnerabilities · 1
PT-2014-8894
7.5
2014-12-03
Invision Power · Invision Power Board · CVE-2014-9239
**Name of the Vulnerable Software and Affected Versions** Invision Power Board versions 3.3.x through 3.4.7 **Description** The issue allows remote attackers to execute arbitrary SQL commands via the `id[]` parameter in the IPS Connect service, located at the "interface/ipsconnect/ipsconnect.php" endpoint. **Recommendations** For versions 3.3.x through 3.4.7, update to a version released after 20141114 to resolve the issue.