Vulnerability Name: | CVE-2016-6174 (CCN-114808) | ||||||||||||
Assigned: | 2016-07-07 | ||||||||||||
Published: | 2016-07-07 | ||||||||||||
Updated: | 2020-06-03 | ||||||||||||
Summary: | applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.1.13, when used with PHP before 5.4.24 or 5.5.x before 5.5.8, allows remote attackers to execute arbitrary code via the content_class parameter. | ||||||||||||
CVSS v3 Severity: | 8.1 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H) 7.1 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-noinfo | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-6174 Source: MISC Type: Exploit http://karmainsecurity.com/KIS-2016-11 Source: APPLE Type: UNKNOWN APPLE-SA-2016-09-20 Source: MISC Type: UNKNOWN http://packetstormsecurity.com/files/137804/IPS-Community-Suite-4.1.12.3-PHP-Code-Injection.html Source: CCN Type: Full-Disclosure Mailing List, Thu, 07 Jul 2016 17:56:11 +0200 [KIS-2016-11] IPS Community Suite <= 4.1.12.3 Autoloaded PHP Code Injection Vulnerability Source: FULLDISC Type: Exploit 20160707 [KIS-2016-11] IPS Community Suite <= 4.1.12.3 Autoloaded PHP Code Injection Vulnerability Source: BID Type: UNKNOWN 91732 Source: CCN Type: BID-91732 IPS Community Suite CVE-2016-6174 PHP Code Injection Vulnerability Source: XF Type: UNKNOWN ipscommunitysuite-cve20166174-code-exec(114808) Source: CCN Type: Invision Power Services Web site IPS Community Suite 4 - Forums, CMS, eCommerce more - Invision Power Services Source: CONFIRM Type: UNKNOWN https://invisionpower.com/release-notes/4113-r44/ Source: CCN Type: Packet Storm Security [07-07-2016] IPS Community Suite 4.1.12.3 PHP Code Injection Source: CCN Type: Apple security document HT207170 About the security content of macOS Sierra 10.12 Source: CONFIRM Type: UNKNOWN https://support.apple.com/HT207170 Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [07-11-2016] Source: EXPLOIT-DB Type: UNKNOWN 40084 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Denotes that component is vulnerable | ||||||||||||
BACK |