PT-2005-2897 · Invision · Invision Blog

James Bercegay

·

Published

2005-06-09

·

Updated

2016-10-18

·

CVE-2005-1946

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Invision Blog versions prior to 1.1.2 Final
Description The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the eid parameter to an editentry, replyentry, or editcomment action, or the mid parameter to an aboutme action.
Recommendations For versions prior to 1.1.2 Final, update to version 1.1.2 Final or later to resolve the issue. As a temporary workaround, consider restricting access to the editentry, replyentry, editcomment, and aboutme actions to minimize the risk of exploitation. Avoid using the eid and mid parameters in the affected actions until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1946

Affected Products

Invision Blog