CVE-2016-6174
high · 8.1applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.1.13, when used with PHP before 5.4.24 or 5.5.x before 5.5.8, allows remote attackers to execute arbitrary code via the content_class parameter.
8.1
CVSS
12.3%
EPSS (exploit prob.)
96th
EPSS percentile
2016-07-12
Published
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| invisioncommunity | invision_power_board | <= 4.1.12.3 |
| php | php | <= 5.4.23 |
| php | php | 5.5.0 |
| php | php | 5.5.0 |
| php | php | 5.5.0 |
| php | php | 5.5.0 |
| php | php | 5.5.0 |
| php | php | 5.5.0 |
| php | php | 5.5.0 |
| php | php | 5.5.0 |
| php | php | 5.5.0 |
| php | php | 5.5.0 |
| php | php | 5.5.0 |
| php | php | 5.5.0 |
| php | php | 5.5.0 |
| php | php | 5.5.1 |
| php | php | 5.5.2 |
| php | php | 5.5.3 |
| php | php | 5.5.4 |
| php | php | 5.5.5 |
| php | php | 5.5.6 |
| php | php | 5.5.7 |
Check a specific version with /api/v1/cve/match.
References
- http://karmainsecurity.com/KIS-2016-11
- http://lists.apple.com/archives/security-announce/2016/Sep/msg00006.html
- http://packetstormsecurity.com/files/137804/IPS-Community-Suite-4.1.12.3-PHP-Code-Injection.html
- http://seclists.org/fulldisclosure/2016/Jul/19
- http://www.securityfocus.com/bid/91732
- https://invisionpower.com/release-notes/4113-r44/
- https://support.apple.com/HT207170
- https://www.exploit-db.com/exploits/40084/
- http://karmainsecurity.com/KIS-2016-11
- http://lists.apple.com/archives/security-announce/2016/Sep/msg00006.html
- http://packetstormsecurity.com/files/137804/IPS-Community-Suite-4.1.12.3-PHP-Code-Injection.html
- http://seclists.org/fulldisclosure/2016/Jul/19
- http://www.securityfocus.com/bid/91732
- https://invisionpower.com/release-notes/4113-r44/
- https://support.apple.com/HT207170
- https://www.exploit-db.com/exploits/40084/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2016-6174