Title : Invision Power Board Threaded View Mode Remote Security Bypass Vulnerability VUPEN ID : VUPEN/ADV-2006-3260 CVE ID : CVE-2006-4155
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-08-11
Technical Description
A vulnerability has been identified in Invision Power Board (IPB), which could be exploited by malicious users to bypass security restrictions. This flaw is due to an error in the threaded view mode ("func_topic_threaded.php"), which could be exploited by attackers to gain unauthorized access to certain posts outside a topic.