PHP.Invision.Power.Board.Search.PHP.st.SQL.Injection

description-logoDescription

It indicates an SQL Injection attack against Invision Power Board Search. Invision Power Board Search is vulnerable to an SQL Injection Attack in the ?search.php? script. Malicious attackers can use the vulnerability to corrupt SQL queries by modifying the ?st? variable.

affected-products-logoAffected Products

Invision Power Services Invision Board 2.0 PDR3 and earlier versions.

Impact logoImpact

Access sensitive data, Execute arbitrary commands

recomended-action-logoRecommended Actions

Apply appropriate patch from the vendor or Upgrade to non-vulnerable version if available.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)