Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2006-2097
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-2097

Description:
SQL injection vulnerability in func_msg.php in Invision Power Board (IPB) 2.1.4 allows remote attackers to execute arbitrary SQL commands via the from_contact field in a private message (PM).

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/26107

SREASON
  http://securityreason.com/securityalert/813

SAID
  Secunia Advisory: SA19861

OSVDB
  25021

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/432248/100/0/threaded

BID
  17719


Return to the previous page.