Invision Power Board Admin.PHP Cross-site Scripting Vulnerability
BID:18450
Info
Invision Power Board Admin.PHP Cross-site Scripting Vulnerability
| Bugtraq ID: | 18450 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 15 2006 12:00AM |
| Updated: | Jun 15 2006 09:31PM |
| Credit: | Kepche has been credited for the discovery of this vulnerability |
| Vulnerable: |
Invision Power Services Invision Power Board 2.1.6 Invision Power Services Invision Power Board 2.1.5.2006.04.25 Invision Power Services Invision Power Board 2.1.5.2006.03.08 Invision Power Services Invision Board 2.1.6 Invision Power Services Invision Board 2.1.5 Invision Power Services Invision Board 2.1.4 Invision Power Services Invision Board 2.1 Alpha2 Invision Power Services Invision Board 2.1 Invision Power Services Invision Board 2.0.4 Invision Power Services Invision Board 2.0.3 Invision Power Services Invision Board 2.0.2 Invision Power Services Invision Board 2.0 PF2 Invision Power Services Invision Board 2.0 PF1 Invision Power Services Invision Board 2.0 PDR3 Invision Power Services Invision Board 2.0 Alpha 3 Invision Power Services Invision Board 2.0 Invision Power Services Invision Board 1.3.1 Final Invision Power Services Invision Board 1.3 Final Invision Power Services Invision Board 1.3 Invision Power Services Invision Board 1.3 Invision Power Services Invision Board 1.2 Invision Power Services Invision Board 1.1.2 Invision Power Services Invision Board 1.1.1 Invision Power Services Invision Board 1.0.3 Invision Power Services Invision Board 1.0.1 Invision Power Services Invision Board 1.0 |
| Not Vulnerable: | |
Discussion
Invision Power Board Admin.PHP Cross-site Scripting Vulnerability
Invision Power Board is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may use this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie credentials; other attacks are also possible.
Invision Power Board is prone to a cross-site scripting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may use this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie credentials; other attacks are also possible.
Exploit / POC
Invision Power Board Admin.PHP Cross-site Scripting Vulnerability
This issue can be exploited by enticing a user to follow a malicious link to the application.
This issue can be exploited by enticing a user to follow a malicious link to the application.
Solution / Fix
Invision Power Board Admin.PHP Cross-site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
Invision Power Board Admin.PHP Cross-site Scripting Vulnerability
References:
References:
- Invision Board Homepage (Invision Power Services)