peter bassill · operator
$ cve CVE-2016-6174 JSON

CVE-2016-6174 EXPLOIT

8.1
HIGH · CVSS 3.0 · EPSS 12.3% (pctl 96)

Patch early

A public exploit exists.

Description

applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.1.13, when used with PHP before 5.4.24 or 5.5.x before 5.5.8, allows remote attackers to execute arbitrary code via the content_class parameter.

Scoring

CVSS8.1 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS12.29% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploityes
Published2016-07-12
Last modified2026-06-17

Affected (2)

VendorProduct
invisioncommunityinvision power board
phpphp

Public exploits

SourceTitleDate
exploit-dbIPS Community Suite 4.1.12.3 - PHP Code Injection2016-07-11

References

→ the Explorer  ·  watch your stack  ·  NVD