CVE-2006-3544
Estado: ModificadaAlta (7.5)—
Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 1.3 Final allow remote attackers to execute arbitrary SQL commands via the CODE parameter in a (1) Stats, (2) Mail, and (3) Reg action in index.php. NOTE: the developer has disputed this issue, stating that "At no point does the CODE parameter touch the database. The CODE parameter is used in a SWITCH statement to determine which function to run.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.37%
- Percentil entre todas las CVEs puntuadas: 71
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://securityreason.com/securityalert/1225
- http://www.osvdb.org/30084
- http://www.securityfocus.com/archive/1/438961/100/0/threaded
- http://www.securityfocus.com/archive/1/439629/100/0/threaded
- http://www.securityfocus.com/bid/18782
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27555
- http://securityreason.com/securityalert/1225
- http://www.osvdb.org/30084
- http://www.securityfocus.com/archive/1/438961/100/0/threaded
- http://www.securityfocus.com/archive/1/439629/100/0/threaded
- http://www.securityfocus.com/bid/18782
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27555
JSON original (NVD)
Mostrar
{
"id": "CVE-2006-3544",
"cveTags": [
{
"tags": [
"disputed"
],
"sourceIdentifier": "cve@mitre.org"
}
],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-07-13T00:05:00.000",
"references": [
{
"url": "http://securityreason.com/securityalert/1225",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/30084",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/438961/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/439629/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/18782",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27555",
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/1225",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/30084",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/438961/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/439629/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/18782",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27555",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 1.3 Final allow remote attackers to execute arbitrary SQL commands via the CODE parameter in a (1) Stats, (2) Mail, and (3) Reg action in index.php. NOTE: the developer has disputed this issue, stating that \"At no point does the CODE parameter touch the database. The CODE parameter is used in a SWITCH statement to determine which function to run."
},
{
"lang": "es",
"value": "** IMPUGNADA ** Múltiples vulnerabilidades de inyección SQL en Invision Power Board (IPB) 1.3 Final permiten a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro CODE de una acción (1) Stats, (2) Mail, y (3) Reg de index.php. NOTA: el desarrollador ha negado este problema, afirmando que \"En ningún punto el parámetro CODE toca la base de datos. El parámetro CODE se usa en una sentencia SWITCH para determinar qué función ejecutar\"."
}
],
"lastModified": "2026-06-16T22:27:16.700",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:invision_power_services:invision_board:1.3.1_final:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6B42A0B9-628F-4173-8F94-3EACDE1D57AE"
},
{
"criteria": "cpe:2.3:a:invision_power_services:invision_board:1.3_final:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "13A127C8-803E-44A5-BB30-09C351CF3ACD"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}