More Invision Power Board Vulnerabilities

| | Comments (0) | TrackBacks (0)

Six Apart's free support bulletin board for Movable Type has been offline for maintenance since this past weekend. I just saw why on Bugtraq. Looks like there is another SQL injection exploit in Invision Power Board that will grant an attacker admin access. This is a vulnerability in versions prior to 2.1.7. Hopefully they'll get patched and back online soon.

Back in May, I wrote when that forum was exploited and modified to serve up WMF exploits. At that time I let the SANS ISC know about it. So it was pretty funny in June when a Circuit City IPB forum was hacked and it made the tech news. According to MSN search there are still a lot of boards running Invision Power Board 2.1.6. A lot of them are hobby websites that likely learn the hard way about keeping up with security patches.

Categories

0 TrackBacks

Listed below are links to blogs that reference this entry: More Invision Power Board Vulnerabilities.

TrackBack URL for this entry: http://www.infosecblog.org/mt-tb20071121.pl/246

Leave a comment

Powered by Ajax Comments

About this Entry

This page contains a single entry by Roger published on July 18, 2006 10:05 PM.

Microsoft Purchases Wininternals/Sysinternals was the previous entry in this blog.

Vulnerability Scanners is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.

Add to Google
Please contact me by leaving a comment where appropriate. Otherwise, you can click here to reveal an email address for me.
Got Backups? Get Safe Online Remember Rick Rescorla Powered by Movable Type 4.2-en