CVE-2006-2059

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/04/2006
Last modified:
18/10/2018

Description

action_public/search.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary PHP code via a search with a crafted value of the lastdate parameter, which alters the behavior of a regular expression to add a "#e" (execute) modifier.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:invision_power_services:invision_power_board:2.1.5_2006-03-08:*:*:*:*:*:*:*