CVE-2004-1836
Invision Power Top Site List <= 1.1 RC 2 - SQL Injection via Comments ID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-1836. PoCs published by JeiAr.
AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in Invision Power Top Site List versions 1.1 RC 2 and prior. The vulnerability is due to insufficient sanitization of the 'id' URI parameter in the 'comments' feature of the 'index.php' script.
Description
SQL injection vulnerability in index.php in Invision Power Top Site List 1.1 RC 2 and earlier allows remote attackers to execute arbitrary SQL via the id parameter of the comments action.
Exploits (1)
The provided text describes an SQL injection vulnerability in Invision Power Top Site List versions 1.1 RC 2 and prior. The vulnerability is due to insufficient sanitization of the 'id' URI parameter in the 'comments' feature of the 'index.php' script.