CVE-2006-5203
Last modified
CVE-2006-5203 is a vulnerability of currently unknown severity. Invision Power Board (IPB) 2.1.7 and earlier allows remote restricted administrators to inject arbitrary web script or HTML, or execute arbitrary SQL commands, via a forum description that contains a crafted image with PHP code, which is executed when the user visits the "Manage Forums" link in the Admin control panel.. EPSS estimates a 0.87% chance of exploitation in the next 30 days.
Description
Invision Power Board (IPB) 2.1.7 and earlier allows remote restricted administrators to inject arbitrary web script or HTML, or execute arbitrary SQL commands, via a forum description that contains a crafted image with PHP code, which is executed when the user visits the "Manage Forums" link in the Admin control panel.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Invision Power Services | Invision Power Board | <= 2.1.7 |
| Invision Power Services | Invision Power Board | 1.0 |
| Invision Power Services | Invision Power Board | 1.0.1 |
| Invision Power Services | Invision Power Board | 1.0.3 |
| Invision Power Services | Invision Power Board | 1.1.1 |
| Invision Power Services | Invision Power Board | 1.1.2 |
| Invision Power Services | Invision Power Board | 1.2 |
| Invision Power Services | Invision Power Board | 1.3 |
| Invision Power Services | Invision Power Board | 1.3.1_final |
| Invision Power Services | Invision Power Board | 1.3_final |
| Invision Power Services | Invision Power Board | 2.0 |
| Invision Power Services | Invision Power Board | 2.0.0 |
| Invision Power Services | Invision Power Board | 2.0.1 |
| Invision Power Services | Invision Power Board | 2.0.2 |
| Invision Power Services | Invision Power Board | 2.0.3 |
| Invision Power Services | Invision Power Board | 2.0.4 |
| Invision Power Services | Invision Power Board | 2.0.x |
| Invision Power Services | Invision Power Board | 2.0_alpha3 |
| Invision Power Services | Invision Power Board | 2.0_pdr3 |
| Invision Power Services | Invision Power Board | 2.0_pf1 |
| Invision Power Services | Invision Power Board | 2.0_pf2 |
| Invision Power Services | Invision Power Board | 2.1 |
| Invision Power Services | Invision Power Board | 2.1.0 |
| Invision Power Services | Invision Power Board | 2.1.1 |
| Invision Power Services | Invision Power Board | 2.1.2 |
| Invision Power Services | Invision Power Board | 2.1.3 |
| Invision Power Services | Invision Power Board | 2.1.4 |
| Invision Power Services | Invision Power Board | 2.1.5 |
| Invision Power Services | Invision Power Board | 2.1.5_2006-03-08 |
| Invision Power Services | Invision Power Board | 2.1.6 |
| Invision Power Services | Invision Power Board | 2.1_alpha2 |
| Invision Power Services | Invision Power Board | 2.1_beta2 |
| Invision Power Services | Invision Power Board | 2.1_beta3 |
| Invision Power Services | Invision Power Board | 2.1_beta4 |
| Invision Power Services | Invision Power Board | 2.1_beta5 |
| Invision Power Services | Invision Power Board | 2.1_rc1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-5203?
How severe is CVE-2006-5203?
How do I fix CVE-2006-5203?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-5197PDshopPro stores sensitive information under the web root wi…
- CVE-2006-5198The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Soft…
- CVE-2006-5199Adobe Contribute Publishing Server leaks the administrator p…
- CVE-2006-5200Unspecified vulnerability in Adobe Breeze 5 Licensed Server …
- CVE-2006-5201Multiple packages on Sun Solaris, including (1) NSS; (2) Jav…
- CVE-2006-5202Linksys WRT54g firmware 1.00.9 does not require credentials …
- CVE-2006-5204Cross-site scripting (XSS) vulnerability in action_admin/mem…
- CVE-2006-5205Directory traversal vulnerability in Invision Gallery 2.0.7 …
- CVE-2006-5206SQL injection vulnerability in Invision Gallery 2.0.7 allows…
- CVE-2006-5207PHP remote file inclusion vulnerability in images/smileys/sm…
- CVE-2006-5208Multiple SQL injection vulnerabilities in PHP Classifieds 7.…
- CVE-2006-5209PHP remote file inclusion vulnerability in admin/admin_topic…
Are you affected by CVE-2006-5203?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
