CVE-2006-2097
Invision Power Board < 2.1.4 - SQL Injection via Private Message From Contact Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2097. PoCs published by Ykstortion Security.
AI-analyzed exploit summary This exploit targets a SQL injection vulnerability in IPB (Invision Power Board) <= 2.1.4, allowing an authenticated attacker to extract password hashes from the database by leveraging the private messaging system.
Description
SQL injection vulnerability in func_msg.php in Invision Power Board (IPB) 2.1.4 allows remote attackers to execute arbitrary SQL commands via the from_contact field in a private message (PM).
Exploits (1)
This exploit targets a SQL injection vulnerability in IPB (Invision Power Board) <= 2.1.4, allowing an authenticated attacker to extract password hashes from the database by leveraging the private messaging system.