peter bassill · operator
$ cve CVE-2004-1536 JSON

CVE-2004-1536 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.4% (pctl 84)

Patch early

A public exploit exists.

Description

SQL injection vulnerability in index.php in the ibProArcade module for Invision Power Board (IPB) 1.x and 2.x allows remote attackers to execute arbitrary SQL commands via the cat parameter.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.42% — more likely to be exploited than 84% of all CVEs
On CISA KEVno
Public exploityes
Published2004-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
ipbproarcadeipbproarcade

Public exploits

SourceTitleDate
exploit-dbIPBProArcade 2.5 - SQL Injection2004-11-20

References

→ the Explorer  ·  watch your stack  ·  NVD