VulnerabilityModified
CVE-2005-3549
Direct code injection vulnerability in Task Manager in Invision Power Board 2.0.1 allows limited remote attackers to execute arbitrary code by referencing the file in "Task PHP File To Run" field and selecting "Run Task Now".
MEDIUM 6.5EPSS 1.87%
Does this matter?
Lower severity and a low EPSS score (1.87%). Track it; it rarely justifies an emergency change on its own.
Description
Direct code injection vulnerability in Task Manager in Invision Power Board 2.0.1 allows limited remote attackers to execute arbitrary code by referencing the file in "Task PHP File To Run" field and selecting "Run Task Now".
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.87% probability · 78th percentile
- CISA KEV
- Not listed
- Affected
- invision power services/invision board
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/17443Patch, Vendor Advisory
- http://www.securityfocus.com/archive/1/415798/30/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40003
- http://secunia.com/advisories/17443Patch, Vendor Advisory
- http://www.securityfocus.com/archive/1/415798/30/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40003
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.