SQL injection vulnerability in xmlout.php in Invision Power Board (IP.Board or IPB) 2.2.x and 2.3.x allows remote attackers to execute arbitrary SQL commands via the name parameter.
| Software | From | Fixed in |
|---|---|---|
| invision_power_services / invision_power_board | 2.2 | 2.2.x |
| invision_power_services / invision_power_board | 2.3 | 2.3.x |