IP. Board IP. Content module "cid" SQL Injection Vulnerability
Released on: 2014-09-04
Updated on: 2014-09-05
Affected Systems:
Invisionpower IP. Content 2.3.6
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2014-0485
IP. Content is a Content management application for IPS Community Suite.
IP. board IP. the Content module does not effectively filter admin/applications_addon/ips/ccs/extensions/search/engines/SQL. the "cid" GET parameter value in php has a security vulnerability in implementation, which can cause arbitrary SQL code injection. Affected Versions: 2.3.6 and earlier versions.
<* Source: vendor
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Invisionpower
-------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Www.invisionpower.com
IP. Content:
Http://community.invisionpower.com/topic/402014-ipcontent-23x-security-update/
Refer:
Jamieson O 'Reilly:
Http://dringen.blogspot.com.au/2014/07/invision-power-board-blind-sql.html
This article permanently updates the link address: