CVE-2014-9239: Invisioncommunity Invision Power Board
High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.
SQL injection vulnerability in the IPS Connect service (interface/ipsconnect/ipsconnect.php) in Invision Power Board (aka IPB or IP.Board) 3.3.x and 3.4.x through 3.4.7 before 20141114 allows remote attackers to execute arbitrary SQL commands via the id[] parameter.
Affected products
- Invisioncommunity Invision Power Board: version 3.3.0 only; version 3.3.1 only; version 3.3.2 only; version 3.3.3 only; version 3.3.4 only; version 3.4.0 only; …
- Invisionpower Invision Power Board: version 3.4.7 only
Published 2014-12-03. Last modified 2026-06-17.