CVE-2004-1536
UnknownEPSS 2.42%
Last modified
CVE-2004-1536 is a vulnerability of currently unknown severity. SQL injection vulnerability in index.php in the ibProArcade module for Invision Power Board (IPB) 1.x and 2.x allows remote attackers to execute arbitrary SQL commands via the cat parameter.. EPSS estimates a 2.42% chance of exploitation in the next 30 days.
Description
SQL injection vulnerability in index.php in the ibProArcade module for Invision Power Board (IPB) 1.x and 2.x allows remote attackers to execute arbitrary SQL commands via the cat parameter.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ipbproarcade | Ipbproarcade | <= 2.5 |
References
- http://secunia.com/advisories/13260Vendor Advisory
- http://secunia.com/advisories/13260Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-1536?
SQL injection vulnerability in index.php in the ibProArcade module for Invision Power Board (IPB) 1.x and 2.x allows remote attackers to execute arbitrary SQL commands via the cat parameter.
How severe is CVE-2004-1536?
Severity scoring for CVE-2004-1536 is pending analysis. The EPSS model estimates a 2.42% probability of exploitation in the next 30 days.
How do I fix CVE-2004-1536?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2004
- CVE-2004-1530SQL injection vulnerability in the Event Calendar module 2.1…
- CVE-2004-1531SQL injection vulnerability in post.php in Invision Power Bo…
- CVE-2004-1532AppServ 2.5.x and earlier installs a default username and pa…
- CVE-2004-1533Buffer overflow in pop3svr.exe for DMS POP3 1.5.3.27 and ear…
- CVE-2004-1534ZoneAlarm and ZoneAlarm Pro before 5.5.062, with ad-blocking…
- CVE-2004-1535PHP remote file inclusion vulnerability in admin_cash.php fo…
- CVE-2004-1537Cross-site scripting (XSS) vulnerability in popup.php in PHP…
- CVE-2004-1538SQL injection vulnerability in include.php in PHPKIT 1.6.03 …
- CVE-2004-1539Halo: Combat Evolved 1.05 and earlier allows remote game ser…
- CVE-2004-1540ZyXEL Prestige 623, 650, and 652 HW Routers, and possibly ot…
- CVE-2004-1541SecureCRT 4.0, 4.1, and possibly other versions, allows remo…
- CVE-2004-1542Buffer overflow in Soldier of Fortune II 1.03 Gold and earli…
Are you affected by CVE-2004-1536?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
