PT-2005-4337 · Invision · Invision Power Board
Published
2005-11-16
·
Updated
2018-10-19
·
CVE-2005-3548
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Invision Power Board (IP.Board) version 2.0.1
Description
A directory traversal issue exists in the Task Manager of Invision Power Board, allowing limited remote attackers to include files by using a .. (dot dot) in the
Task PHP File To Run field.Recommendations
For Invision Power Board (IP.Board) version 2.0.1, consider restricting access to the Task Manager or limiting the ability to specify files in the
Task PHP File To Run field until a fix is available.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Invision Power Board