PT-2005-4338 · Invision · Invision Power Board

Published

2005-11-16

·

Updated

2018-10-19

·

CVE-2005-3549

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Invision Power Board version 2.0.1
Description A direct code injection issue in the Task Manager allows limited remote attackers to execute arbitrary code. This is achieved by referencing a file in the Task PHP File To Run field and then selecting Run Task Now.
Recommendations For Invision Power Board version 2.0.1, consider restricting access to the Task Manager or removing the ability to reference external files in the Task PHP File To Run field until a fix is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3549

Affected Products

Invision Power Board