CVE-2004-1531

Invision Power Board 2.0.0-2.0.2 - SQL Injection via qpid Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-1531. PoCs published by RusH.

AI-analyzed exploit summary This Perl script exploits a SQL injection vulnerability in Invision Power Board versions 2.0.0 to 2.0.2. It allows an attacker to extract user credentials, including member IDs, usernames, and password hashes, by manipulating the 'qpid' parameter in a crafted HTTP request.

Description

SQL injection vulnerability in post.php in Invision Power Board (IPB) 2.0.0 through 2.0.2 allows remote attackers to execute arbitrary SQL commands via the qpid parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by RusH · perlwebappsphp
https://www.exploit-db.com/exploits/648

This Perl script exploits a SQL injection vulnerability in Invision Power Board versions 2.0.0 to 2.0.2. It allows an attacker to extract user credentials, including member IDs, usernames, and password hashes, by manipulating the 'qpid' parameter in a crafted HTTP request.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Invision Power Board v2.0.0 - 2.0.2
Auth required
Prerequisites: Valid session ID (SID) · Existing forum and topic numbers · Table prefix if known
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=111462421824202&w=2
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/11703
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=111454805209191&w=2
Patch third-party-advisory x_refsource_secunia
http://secunia.com/advisories/13245
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/18164
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=110079592702417&w=2

Scores

EPSS 0.0134
EPSS Percentile 67.6%

Details

Status published
Products (3)
invision_power_services/invision_board 2.0
invision_power_services/invision_board 2.0.1
invision_power_services/invision_board 2.0.2
Published Dec 31, 2004
Tracked Since Feb 18, 2026