SQL injection vulnerability in xmlout.php in Invision Power Board (IP.Board or IPB) 2.2.x and 2.3.x allows remote attackers to execute arbitrary SQL commands via the name parameter.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2008-09-22 11:34
Updated : 2011-03-07 19:12
NVD link : CVE-2008-4171
Mitre link : CVE-2008-4171
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
invision_power_services
- invision_power_board