← Vulnerability feed

Vulnerability record · CVE-2006-3544 · published 13 July 2006

CVE-2006-3544: Invision power services invision board vulnerability

IInvision Power Services · Invision Board

Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 1.3 Final allow remote attackers to execute arbitrary SQL commands via the CODE parameter in a (1) Stats, (2) Mail, and (3) Reg action in index.php. NOTE: the developer has disputed this issue, stating that "At no point does the CODE parameter touch the database. The CODE parameter is used in a SWITCH statement to determine which function to run.

7.5 CVSS 2.0 High EPSS 1.4% · top 29.1%
7.5CVSS 2.0 base score
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 1.3 Final allow remote attackers to execute arbitrary SQL commands via the CODE parameter in a (1) Stats, (2) Mail, and (3) Reg action in index.php. NOTE: the developer has disputed this issue, stating that "At no point does the CODE parameter touch the database. The CODE parameter is used in a SWITCH statement to determine which function to run.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-3544 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-0338Invision power services invision board vulnerabilitySQL injection vulnerability in search.php for Invision Board Forum allows remote attackers to execute arbitrary SQL queries via the st parameter.EPSS 2.4%7.5CVE-2005-1598Invision power services invision board vulnerabilitySQL injection vulnerability in Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via a crafted c…EPSS 14%7.5CVE-2005-1070Invision power services invision board vulnerabilitySQL injection vulnerability in index.php in Invision Power Board 1.3.1 Final and earlier allows remote attackers to execute arbitrary SQL commands vi…EPSS 1.1%7.5CVE-2004-1531Invision power services invision board vulnerabilitySQL injection vulnerability in post.php in Invision Power Board (IPB) 2.0.0 through 2.0.2 allows remote attackers to execute arbitrary SQL commands v…EPSS 1.3%7.5CVE-2004-1785Invision power services invision board vulnerabilitySQL injection vulnerability in calendar.php for Invision Power Board 1.3 allows remote attackers to execute arbitrary SQL commands via the m paramete…EPSS 1.4%6.8CVE-2004-0359Invision power services invision board vulnerabilityCross-site scripting (XSS) vulnerability in index.php for Invision Power Board 1.3 final allows remote attackers to execute arbitrary script as other…EPSS 5.6%6.5CVE-2005-3549Invision power services invision board vulnerabilityDirect code injection vulnerability in Task Manager in Invision Power Board 2.0.1 allows limited remote attackers to execute arbitrary code by refere…EPSS 1.9%5.0CVE-2006-2061Invision power services invision board vulnerabilitySQL injection vulnerability in lib/func_taskmanager.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to exec…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2006-3544), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.