Intrusion Prevention

PHP.Invision.Power.Board.Search.PHP.st.SQL.Injection

Description

It indicates an SQL Injection attack against Invision Power Board Search. Invision Power Board Search is vulnerable to an SQL Injection Attack in the ?search.php? script. Malicious attackers can use the vulnerability to corrupt SQL queries by modifying the ?st? variable.

Affected Products

Invision Power Services Invision Board 2.0 PDR3 and earlier versions.

Impact

Access sensitive data, Execute arbitrary commands

Recommended Actions

Apply appropriate patch from the vendor or Upgrade to non-vulnerable version if available.

CVE References

CVE-2004-0338