CVE-2006-2097
Invision Power Services Invision Power Board < 2.1.4 - SQL Injection
Title source: ruleDescription
SQL injection vulnerability in func_msg.php in Invision Power Board (IPB) 2.1.4 allows remote attackers to execute arbitrary SQL commands via the from_contact field in a private message (PM).
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Ykstortion Security · perlwebappsphp
https://www.exploit-db.com/exploits/1733
References (6)
Scores
EPSS
0.0095
EPSS Percentile
76.5%
Details
Status
published
Products (26)
invision_power_services/invision_power_board
1.0
invision_power_services/invision_power_board
1.0.1
invision_power_services/invision_power_board
1.1.1
invision_power_services/invision_power_board
1.1.2
invision_power_services/invision_power_board
1.2
invision_power_services/invision_power_board
1.3
invision_power_services/invision_power_board
1.3.1_final
invision_power_services/invision_power_board
1.3_final
invision_power_services/invision_power_board
2.0.0
invision_power_services/invision_power_board
2.0.1
... and 16 more
Published
Apr 29, 2006
Tracked Since
Feb 18, 2026