Invision Power Board Referer Cross-Site Scripting Vulnerability
BID:11332
Info
Invision Power Board Referer Cross-Site Scripting Vulnerability
| Bugtraq ID: | 11332 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 05 2004 12:00AM |
| Updated: | Oct 05 2004 12:00AM |
| Credit: | Disclosure of this issue is credited to "Alexander Antipov" <[email protected]>. |
| Vulnerable: |
Invision Power Services Invision Board 2.0 |
| Not Vulnerable: | |
Discussion
Invision Power Board Referer Cross-Site Scripting Vulnerability
Reportedly Invision Power Board is affected by a remote cross-site scripting vulnerability. This issue is due to a failure of the application to validate or sanitize user supplied input prior to including it in dynamic Web content.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the vulnerable application, facilitating the theft of cookie-based authentication credentials as well as other attacks.
Reportedly Invision Power Board is affected by a remote cross-site scripting vulnerability. This issue is due to a failure of the application to validate or sanitize user supplied input prior to including it in dynamic Web content.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the vulnerable application, facilitating the theft of cookie-based authentication credentials as well as other attacks.
Exploit / POC
Invision Power Board Referer Cross-Site Scripting Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Invision Power Board Referer Cross-Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Invision Power Board Referer Cross-Site Scripting Vulnerability
References:
References:
- Invision Board Homepage (Invision Power Services)
- [MAXPATROL Security Advisories] Cross site scripting in Invision Power Board ("Alexander Antipov"
)