PT-2006-3218 · Invision · Invision Community Blog

Published

2006-05-09

·

Updated

2017-07-20

·

CVE-2006-2251

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Invision Community Blog (ICB) versions 1.1.2 through 1.2
Description The issue allows remote attackers with moderator privileges to execute arbitrary SQL commands. This is achieved via the selectedbids parameter in the do mmod function in mod.php.
Recommendations For versions 1.1.2 through 1.2, consider restricting access to the do mmod function in mod.php to minimize the risk of exploitation. Avoid using the selectedbids parameter in the affected module until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2251

Affected Products

Invision Community Blog