PT-2005-4338 · Invision · Invision Power Board
Published
2005-11-16
·
Updated
2018-10-19
·
CVE-2005-3549
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Invision Power Board version 2.0.1
Description
A direct code injection issue in the Task Manager allows limited remote attackers to execute arbitrary code. This is achieved by referencing a file in the
Task PHP File To Run field and then selecting Run Task Now.Recommendations
For Invision Power Board version 2.0.1, consider restricting access to the Task Manager or removing the ability to reference external files in the
Task PHP File To Run field until a fix is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Invision Power Board