Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SQL injection vulnerability in the topic deletion functionality (post_delete function in func_mod.php) for Invision Power Board 2.1.5 allows remote authenticated moderators to execute arbitrary SQL commands via the selectedpids parameter, which bypasses an integer value check when the $id variable is an array.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Invision Power Board Func_mod.PHP SQL注入漏洞
Vulnerability Description
Invision Power Board 2.1.5 的标题删除功能(func_mod.php中的post_delete 函数)存在SQL注入漏洞,远程认证版主可以借助selectedpids参数执行任意SQL指令。该参数可在$id变量为数组时绕过整数值检查。
CVSS Information
N/A
Vulnerability Type
N/A