CVE-2016-6174

Source
https://nvd.nist.gov/vuln/detail/CVE-2016-6174
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-6174.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-6174
Published
2016-07-12T19:59:09Z
Modified
2025-04-12T13:45:28.366046Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.1.13, when used with PHP before 5.4.24 or 5.5.x before 5.5.8, allows remote attackers to execute arbitrary code via the content_class parameter.

References

Affected packages

Git / github.com/php/php-src

Affected versions

Other

NEWS
NEWS-cvs2svn

php-5.*

php-5.3.23RC1
php-5.4.23
php-5.4.23RC1
php-5.4.4RC2
php-5.5.2
php-5.5.4
php-5.5.7
php-5.5.7RC1