Release date:
Updated on: 2013-05-23
Affected Systems:
Invision Power Board 3.4.4
Description:
--------------------------------------------------------------------------------
Invision Power Board is a popular PHP Forum program.
The Invision Power Board does not correctly verify the input content of the User Email field on the registration page, which allows remote attackers to modify the logon password of any User. Attackers can remotely execute code by modifying the password of the administrator account. Successful exploitation of this vulnerability requires the attacker to obtain the username and registered email address of the target account.
<* Source: John JEAN
Link: http://cxsecurity.com/issue/WLB-2013050108
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Invision Power Board
--------------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.invisionpower.com/
Http://community.invisionpower.com/topic/385207-ipboard-32x-33x-and-34x-critical-security-update/