|
RETIRED: Invision Power Board Index.PHP ST Parameter SQL Injection Vulnerability
Invision Power Board is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query. A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation. Update: The vendor states that this is not a vulnerability, because the affected parameter is passed through PHP's 'intval' prior to its use. This BID is therefore being retired. |
|
|
Privacy Statement |