PT-2005-2897 · Invision · Invision Blog
James Bercegay
·
Published
2005-06-09
·
Updated
2016-10-18
·
CVE-2005-1946
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Invision Blog versions prior to 1.1.2 Final
Description
The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the
eid parameter to an editentry, replyentry, or editcomment action, or the mid parameter to an aboutme action.Recommendations
For versions prior to 1.1.2 Final, update to version 1.1.2 Final or later to resolve the issue. As a temporary workaround, consider restricting access to the editentry, replyentry, editcomment, and aboutme actions to minimize the risk of exploitation. Avoid using the
eid and mid parameters in the affected actions until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Invision Blog