Invision Power Board Index.php Query String Cross-Site Scripting Vulnerability
BID:10804
Info
Invision Power Board Index.php Query String Cross-Site Scripting Vulnerability
| Bugtraq ID: | 10804 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0359 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 26 2004 12:00AM |
| Updated: | Jul 12 2009 06:16AM |
| Credit: | Discovery of this issue is credited to Electrobug. |
| Vulnerable: |
Invision Power Services Invision Board 2.0 PF2 Invision Power Services Invision Board 2.0 PF1 Invision Power Services Invision Board 2.0 PDR3 Invision Power Services Invision Board 2.0 Alpha 3 Invision Power Services Invision Board 2.0 |
| Not Vulnerable: | |
Discussion
Invision Power Board Index.php Query String Cross-Site Scripting Vulnerability
A vulnerability has been reported to exist in Invision Power Board that may allow a remote user to launch cross-site scripting attacks.
This vulnerability makes it possible for an attacker to construct a malicious link containing HTML or script code that may be rendered in a user's browser upon visiting that link. This attack would occur in the security context of the site.
Successful exploitation of this attack may allow an attacker to steal cookie-based authentication credentials. Other attacks are also possible.
A vulnerability has been reported to exist in Invision Power Board that may allow a remote user to launch cross-site scripting attacks.
This vulnerability makes it possible for an attacker to construct a malicious link containing HTML or script code that may be rendered in a user's browser upon visiting that link. This attack would occur in the security context of the site.
Successful exploitation of this attack may allow an attacker to steal cookie-based authentication credentials. Other attacks are also possible.
Exploit / POC
Invision Power Board Index.php Query String Cross-Site Scripting Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Invision Power Board Index.php Query String Cross-Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Invision Power Board Index.php Query String Cross-Site Scripting Vulnerability
References:
References:
- Invision Board Homepage (Invision Power Services)