Invision Power · Invision Power Board · CVE-2006-1153
**Name of the Vulnerable Software and Affected Versions**
D2-Shoutbox version 4.2
**Description**
The issue allows remote attackers to execute arbitrary SQL commands via the `load` parameter when performing a Shoutbox action through Invision Power Board (IPB). This is a SQL injection vulnerability.
**Recommendations**
For D2-Shoutbox version 4.2, consider restricting access to the `load` parameter in the affected API endpoint until a patch is available. As a temporary workaround, avoid using the `load` parameter when performing Shoutbox actions through IPB. At the moment, there is no information about a newer version that contains a fix for this vulnerability.