CVE-2005-1817
Invision Power Board 1.0-1.3 - Unauthenticated Arbitrary Forum Post Editing via Direct Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-1817. PoCs published by V[i]RuS.
AI-analyzed exploit summary This batch script automates the exploitation of an unauthorized access vulnerability in Invision Power Board, allowing a moderator to edit posts owned by other moderators via a crafted HTTP GET request. It constructs a URL with user-provided parameters to bypass insufficient authentication checks.
Description
Invision Power Board (IPB) 1.0 through 1.3 allows remote attackers to edit arbitrary forum posts via a direct request to index.php with modified parameters.
Exploits (1)
This batch script automates the exploitation of an unauthorized access vulnerability in Invision Power Board, allowing a moderator to edit posts owned by other moderators via a crafted HTTP GET request. It constructs a URL with user-provided parameters to bypass insufficient authentication checks.