|
|
Info |
Last Modified |
| about 1 year ago |
|
|
|
|
|
Description |
Invision Power Board contains a flaw that allows a remote attacker to execute arbitrary files outside of the web path. The issue is due to the 'Task PHP File to Run' field not properly sanitizing user input, specifically directory traversal style attacks (../../).
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Available
OSVDB:
Web Related
|
|
Solution |
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
|
|
Products |
|
Invision Power Board
 |
2.0.1 |
|
|
|
|
Credit |
- Anti Matter - antimatter
gmail.com -
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|