Invision Power Board Multiple HTML Injection Vulnerabilities
BID:18571
CVE-2006-3197 |Info
Invision Power Board Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 18571 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 21 2006 12:00AM |
| Updated: | Jul 12 2006 03:58PM |
| Credit: | The vendor reported these issues. |
| Vulnerable: |
Invision Power Services Invision Power Board 2.1.5.2006.04.25 Invision Power Services Invision Power Board 2.1.5.2006.03.08 Invision Power Services Invision Board 2.1.6 Invision Power Services Invision Board 2.1.5 Invision Power Services Invision Board 2.1.4 Invision Power Services Invision Board 2.1 Alpha2 Invision Power Services Invision Board 2.1 |
| Not Vulnerable: |
Invision Power Services Invision Board 2.1.6 2006-06-19 |
Discussion
Invision Power Board Multiple HTML Injection Vulnerabilities
Invision Power Board is reported prone to multiple HTML-injection vulnerabilities.
Since the application fails to filter HTML content, attackers can exploit various latent vulnerabilities in web-based applications. A successful attack may involve HTML-injection or cross-site scripting issues.
Invision Power Board versions prior to 2.1.6 (2006-06-19) are affected by these issues.
Invision Power Board is reported prone to multiple HTML-injection vulnerabilities.
Since the application fails to filter HTML content, attackers can exploit various latent vulnerabilities in web-based applications. A successful attack may involve HTML-injection or cross-site scripting issues.
Invision Power Board versions prior to 2.1.6 (2006-06-19) are affected by these issues.
Exploit / POC
Invision Power Board Multiple HTML Injection Vulnerabilities
Attackers can exploit these issues through a web client.
Attackers can exploit these issues through a web client.
Solution / Fix
Invision Power Board Multiple HTML Injection Vulnerabilities
Solution:
The vendor has released a fix for all 2.1.x versions. Please contact the vendor for information on obtaining fixes.
Solution:
The vendor has released a fix for all 2.1.x versions. Please contact the vendor for information on obtaining fixes.
References
Invision Power Board Multiple HTML Injection Vulnerabilities
References:
References:
- Invision Board Homepage (Invision Power Services)