CVE-2007-4914 (CNNVD-200709-211)
中文标题:
Invision Power Board用户配置文件和订单管理器多个输入验证漏洞
英文标题:
Unspecified vulnerability in the subscriptions manager in Invision Power Board (IPB or IP.Board) 2.3...
漏洞描述
中文描述:
Invision Power Board是一个非常流行的PHP论坛程序。 Invision Power Board的ips_kernel/class_ajax.php文件没有正确地验证用户配置文件中某些字段的输入,允许攻击者注入任意HTML和脚本代码,如果浏览了恶意用户的配置文件就会在管理用户浏览器环境中执行这些代码。成功攻击要求将Invision Power Board配置为使用非iso-8859-1和utf-8字符集。 Invision Power Board的订单管理器在处理支付时存在漏洞,攻击者可以通过提交特制的支付表单修改成员ID。成功利用这个漏洞可以将管理员和版主降级到订单用户组,但要求启用了订单软件包。 <*链接:http://secunia.com/advisories/19830/print/ http://forums.invisionpower.com/index.php?showtopic=237075
英文描述:
Unspecified vulnerability in the subscriptions manager in Invision Power Board (IPB or IP.Board) 2.3.1 before 20070912 allows remote authenticated users to change the member ID and reduce the privilege level of arbitrary users via a crafted payment form, related to (1) class_gw_2checkout.php, (2) class_gw_authorizenet.php, (3) class_gw_nochex.php, (4) class_gw_paypal.php, and (5) class_gw_safshop.php in sources/classes/paymentgateways/.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| invision_power_services | invision_power_board | * | - | - |
cpe:2.3:a:invision_power_services:invision_power_board:*:*:*:*:*:*:*:*
|
| invision_power_services | invision_power_board | 2.1.5_2006-03-08 | - | - |
cpe:2.3:a:invision_power_services:invision_power_board:2.1.5_2006-03-08:*:*:*:*:*:*:*
|
| invision_power_services | invision_power_board | 2.1.5_2006-04-25 | - | - |
cpe:2.3:a:invision_power_services:invision_power_board:2.1.5_2006-04-25:*:*:*:*:*:*:*
|
| invision_power_services | invision_power_board | 2.1.6 | - | - |
cpe:2.3:a:invision_power_services:invision_power_board:2.1.6:*:*:*:*:*:*:*
|
| invision_power_services | invision_power_board | 2.2 | - | - |
cpe:2.3:a:invision_power_services:invision_power_board:2.2:*:*:*:*:*:*:*
|
| invision_power_services | invision_power_board | 2.2.1 | - | - |
cpe:2.3:a:invision_power_services:invision_power_board:2.2.1:*:*:*:*:*:*:*
|
| invision_power_services | invision_power_board | 2.2.2 | - | - |
cpe:2.3:a:invision_power_services:invision_power_board:2.2.2:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
CVSS评分详情
AV:N/AC:M/Au:S/C:P/I:P/A:P
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2007-4914 |
2025-11-11 15:17:55 | 2025-11-11 07:32:46 |
| NVD | nvd_CVE-2007-4914 |
2025-11-11 14:52:12 | 2025-11-11 07:41:33 |
| CNNVD | cnnvd_CNNVD-200709-211 |
2025-11-11 15:08:58 | 2025-11-11 07:49:20 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 授权问题
- cnnvd_id: 未提取 -> CNNVD-200709-211
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- cvss_score: 未提取 -> 6.0
- cvss_vector: NOT_EXTRACTED -> AV:N/AC:M/Au:S/C:P/I:P/A:P
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 7
- data_sources: ['cve'] -> ['cve', 'nvd']