CVE-2006-2059
CVE-2006-2059
action_public/search.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary PHP code via a search with a crafted value of the lastdate parameter, which alters the behavior of a regular expression to add a "#e" (execute) modifier.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/1720unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://forums.invisionpower.com/index.php?showtopic=213374http://secunia.com/advisories/19830http://securityreason.com/securityalert/796https://exchange.xforce.ibmcloud.com/vulnerabilities/26070http://www.osvdb.org/25005http://www.securityfocus.com/archive/1/431990/100/0/threadedhttp://www.securityfocus.com/archive/1/432226/100/0/threadedhttp://www.securityfocus.com/archive/1/432451/100/0/threadedhttp://www.securityfocus.com/archive/1/439607/100/0/threadedhttp://www.securityfocus.com/bid/17695http://www.vupen.com/english/advisories/2006/1534