CVE-2014-4928

Description

SQL injection vulnerability in Invision Power Board (aka IPB or IP.Board) before 3.4.6 allows remote attackers to execute arbitrary SQL commands via the cId parameter.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.37

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2014-3149,CVE-2014-4928,CVE-2014-5106,CVE-2014-9239 are affected in Invision Power Board 3.4.5Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234