{"id":"CVE-2016-6174","details":"applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power Board) before 4.1.13, when used with PHP before 5.4.24 or 5.5.x before 5.5.8, allows remote attackers to execute arbitrary code via the content_class parameter.","modified":"2026-08-07T11:31:20.983306426Z","published":"2016-07-12T19:59:09.567Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"last_affected":"4.1.12.3"}],"source":"CPE_RANGE","vendor_product":"invisioncommunity:invision_power_board","cpes":["cpe:2.3:a:invisioncommunity:invision_power_board:*:*:*:*:*:*:*:*"]}]},"references":[{"type":"WEB","url":"http://lists.apple.com/archives/security-announce/2016/Sep/msg00006.html"},{"type":"WEB","url":"http://packetstormsecurity.com/files/137804/IPS-Community-Suite-4.1.12.3-PHP-Code-Injection.html"},{"type":"WEB","url":"http://www.securityfocus.com/bid/91732"},{"type":"WEB","url":"https://invisionpower.com/release-notes/4113-r44/"},{"type":"WEB","url":"https://support.apple.com/HT207170"},{"type":"WEB","url":"https://www.exploit-db.com/exploits/40084/"},{"type":"EVIDENCE","url":"http://karmainsecurity.com/KIS-2016-11"},{"type":"EVIDENCE","url":"http://seclists.org/fulldisclosure/2016/Jul/19"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/php/php-src","events":[{"introduced":"0"},{"last_affected":"733fc5cd48cbbc0ace1530d869e5d69a79049b2e"},{"introduced":"2c2d0de09e522fe097bfcebfb758171eb6aa5270"},{"last_affected":"6daaf1103b9ea36ecf04c5cffee9e8287fdf39c7"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"5.4.23"},{"introduced":"5.5.0"},{"last_affected":"5.5.0"},{"introduced":"5.5.0-alpha1"},{"last_affected":"5.5.0-alpha1"},{"introduced":"5.5.0-alpha2"},{"last_affected":"5.5.0-alpha2"},{"introduced":"5.5.0-alpha3"},{"last_affected":"5.5.0-alpha3"},{"introduced":"5.5.0-alpha4"},{"last_affected":"5.5.0-alpha4"},{"introduced":"5.5.0-alpha5"},{"last_affected":"5.5.0-alpha5"},{"introduced":"5.5.0-alpha6"},{"last_affected":"5.5.0-alpha6"},{"introduced":"5.5.0-beta1"},{"last_affected":"5.5.0-beta1"},{"introduced":"5.5.0-beta2"},{"last_affected":"5.5.0-beta2"},{"introduced":"5.5.0-beta3"},{"last_affected":"5.5.0-beta3"},{"introduced":"5.5.0-beta4"},{"last_affected":"5.5.0-beta4"},{"introduced":"5.5.0-rc1"},{"last_affected":"5.5.0-rc1"},{"introduced":"5.5.0-rc2"},{"last_affected":"5.5.0-rc2"},{"introduced":"5.5.1"},{"last_affected":"5.5.1"},{"introduced":"5.5.2"},{"last_affected":"5.5.2"},{"introduced":"5.5.3"},{"last_affected":"5.5.3"},{"introduced":"5.5.4"},{"last_affected":"5.5.4"},{"introduced":"5.5.5"},{"last_affected":"5.5.5"},{"introduced":"5.5.6"},{"last_affected":"5.5.6"},{"introduced":"5.5.7"},{"last_affected":"5.5.7"}],"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:php:php:*:*:*:*:*:*:*:*","cpe:2.3:a:php:php:5.5.0:*:*:*:*:*:*:*","cpe:2.3:a:php:php:5.5.0:alpha1:*:*:*:*:*:*","cpe:2.3:a:php:php:5.5.0:alpha2:*:*:*:*:*:*","cpe:2.3:a:php:php:5.5.0:alpha3:*:*:*:*:*:*","cpe:2.3:a:php:php:5.5.0:alpha4:*:*:*:*:*:*","cpe:2.3:a:php:php:5.5.0:alpha5:*:*:*:*:*:*","cpe:2.3:a:php:php:5.5.0:alpha6:*:*:*:*:*:*","cpe:2.3:a:php:php:5.5.0:beta1:*:*:*:*:*:*","cpe:2.3:a:php:php:5.5.0:beta2:*:*:*:*:*:*","cpe:2.3:a:php:php:5.5.0:beta3:*:*:*:*:*:*","cpe:2.3:a:php:php:5.5.0:beta4:*:*:*:*:*:*","cpe:2.3:a:php:php:5.5.0:rc1:*:*:*:*:*:*","cpe:2.3:a:php:php:5.5.0:rc2:*:*:*:*:*:*","cpe:2.3:a:php:php:5.5.1:*:*:*:*:*:*:*","cpe:2.3:a:php:php:5.5.2:*:*:*:*:*:*:*","cpe:2.3:a:php:php:5.5.3:*:*:*:*:*:*:*","cpe:2.3:a:php:php:5.5.4:*:*:*:*:*:*:*","cpe:2.3:a:php:php:5.5.5:*:*:*:*:*:*:*","cpe:2.3:a:php:php:5.5.6:*:*:*:*:*:*:*","cpe:2.3:a:php:php:5.5.7:*:*:*:*:*:*:*"]}}],"versions":["5.5.0","5.5.0-alpha1","5.5.0-alpha2","5.5.0-alpha3","5.5.0-alpha4","5.5.0-alpha5","5.5.0-alpha6","5.5.0-beta1","5.5.0-beta2","5.5.0-beta3","5.5.0-beta4","5.5.0-rc1","5.5.0-rc2","5.5.1","5.5.2","5.5.3","5.5.4","5.5.5","5.5.6","5.5.7","php-5.5.7","php-5.5.7RC1","php-5.4.23","php-5.4.23RC1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-6174.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}