CVE-2006-2097

Invision Power Services Invision Power Board < 2.1.4 - SQL Injection

Title source: rule
STIX 2.1

Description

SQL injection vulnerability in func_msg.php in Invision Power Board (IPB) 2.1.4 allows remote attackers to execute arbitrary SQL commands via the from_contact field in a private message (PM).

Exploits (1)

exploitdb WORKING POC VERIFIED
by Ykstortion Security · perlwebappsphp
https://www.exploit-db.com/exploits/1733

Scores

EPSS 0.0095
EPSS Percentile 76.5%

Details

Status published
Products (26)
invision_power_services/invision_power_board 1.0
invision_power_services/invision_power_board 1.0.1
invision_power_services/invision_power_board 1.1.1
invision_power_services/invision_power_board 1.1.2
invision_power_services/invision_power_board 1.2
invision_power_services/invision_power_board 1.3
invision_power_services/invision_power_board 1.3.1_final
invision_power_services/invision_power_board 1.3_final
invision_power_services/invision_power_board 2.0.0
invision_power_services/invision_power_board 2.0.1
... and 16 more
Published Apr 29, 2006
Tracked Since Feb 18, 2026