PT-2005-5367 · Invision Power Services · Ibproarcade
Published
2005-12-31
·
Updated
2008-09-05
·
CVE-2005-4702
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IPBProArcade version 2.5.2
Description
The issue allows remote attackers to inject arbitrary SQL commands via the
gameid parameter in the favorites module in index.php. There is uncertainty regarding the nature of this issue, as it might be related to shell metacharacters or could potentially be a rediscovery of a previously known problem.Recommendations
For IPBProArcade version 2.5.2, consider restricting access to the favorites module in index.php to minimize the risk of exploitation. Avoid using the
gameid parameter in the affected module until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibproarcade