Results 1 to 5 of 5

Thread: Invision Power Board SQL PHP File Inclusion and SQL Injection

  1. #1
    Senior Member newsbot's Avatar
    Join Date
    Sep 2002
    Location
    Thailand
    Posts
    3,766


    Invision Power Board has a PHP file inclusion vulnerability that is trivial to exploit with a web browser and a known location of a php file residing on the target system. Authorisation is not required. The SQL injection vulnerability is somewhat tricky to exploit as there are quite a few restrictions that make creating a successful sql attack vector difficult. Nevertheless a crafty attacker might issue a series of requests that might allow him to gain some information about the target system or even read files from the disk depending on permissions granted to the db account that is used by the forum.

    -</p>

    Make your website safer. Use external penetration testing service. First report ready in one hour!</p>

    **Hidden Content: To see this hidden content your post count must be 1 or greater.**
    clone 'em all

  2. #2
    Senior Member newsbot's Avatar
    Join Date
    Sep 2002
    Location
    Thailand
    Posts
    3,766


    Invision Power Board has a PHP file inclusion vulnerability that is trivial to exploit with a web browser and a known location of a php file residing on the target system. Authorisation is not required. The SQL injection vulnerability is somewhat tricky to exploit as there are quite a few restrictions that make creating a successful sql attack vector difficult. Nevertheless a crafty attacker might issue a series of requests that might allow him to gain some information about the target system or even read files from the disk depending on permissions granted to the db account that is used by the forum.

    -</p>

    Make your website safer. Use external penetration testing service. First report ready in one hour!</p>

    **Hidden Content: To see this hidden content your post count must be 1 or greater.**
    clone 'em all

Similar Threads

  1. IPB - Invision Power Board v3.0.3 + Extras!
    By rev0lut1on in forum แนะนำ Software ต่างๆ
    Replies: 7
    Last Post: 09-01-2010, 10:30 PM
  2. Invision Power Board v2.2.x & Many IP product
    By 101010 in forum PHP,ASP,Javascript, Html
    Replies: 0
    Last Post: 06-10-2007, 03:58 PM
  3. Invision Power Board <2.0.4 SQL injection
    By nizx in forum Hacking, Exploit Articles/Tutorial/Techniques
    Replies: 0
    Last Post: 19-06-2007, 03:06 AM
  4. XSS Cross site scripting Invision Power Board v 2.1.1
    By asylu3 in forum Hacking, Exploit Articles/Tutorial/Techniques
    Replies: 0
    Last Post: 05-08-2006, 10:42 AM

Members who have read this thread : 0

Actions : (View-Readers)

There are no names to display.

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •