Vulnerabilities (CVE)

Filtered by vendor Invision Power Services
Filtered by product Invision Power Board
Angry Yack Logo
Total 42 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-1076 1 Invision Power Services 1 Invision Power Board 2025-04-03 7.5 HIGH N/A
SQL injection vulnerability in index.php, possibly during a showtopic operation, in Invision Power Board (IPB) 2.1.5 allows remote attackers to execute arbitrary SQL commands via the st parameter.
CVE-2006-2498 1 Invision Power Services 1 Invision Power Board 2025-04-03 6.4 MEDIUM N/A
Invision Power Board (IPB) before 2.1.6 allows remote attackers to execute arbitrary PHP script via attack vectors involving (1) the post_icon variable in classes/post/class_post.php and (2) the df value in action_public/moderate.php.