Invision Power Board 'Signature' iFrame Security Vulnerability
BID:28466
Info
Invision Power Board 'Signature' iFrame Security Vulnerability
| Bugtraq ID: | 28466 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6565 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 26 2008 12:00AM |
| Updated: | May 07 2015 05:31PM |
| Credit: | CYBER.DARK.HIMU (SHAHEE_MIRZA) |
| Vulnerable: |
Invision Power Services Invision Power Board 2.3.1 Invision Power Services Invision Power Board 2.2.2 Invision Power Services Invision Power Board 2.2.1 Invision Power Services Invision Power Board 2.2 Invision Power Services Invision Power Board 2.1.6 Invision Power Services Invision Power Board 2.1.5.2006.04.25 Invision Power Services Invision Power Board 2.1.5.2006.03.08 |
| Not Vulnerable: | |
Discussion
Invision Power Board 'Signature' iFrame Security Vulnerability
Invision Power Board (IP.Board) is prone to a security vulnerability that can aid attackers in social-engineering attacks.
Attacker-supplied script code could exploit vulnerabilities in the user's browser or give the user a false sense of security when visiting trusted web pages, which can aid in launching further attacks.
This issue affects IP.Board 2.3.1; other versions may also be affected.
Invision Power Board (IP.Board) is prone to a security vulnerability that can aid attackers in social-engineering attacks.
Attacker-supplied script code could exploit vulnerabilities in the user's browser or give the user a false sense of security when visiting trusted web pages, which can aid in launching further attacks.
This issue affects IP.Board 2.3.1; other versions may also be affected.
Exploit / POC
Invision Power Board 'Signature' iFrame Security Vulnerability
Attackers may exploit this issue through a browser.
The following example is available:
Attackers may exploit this issue through a browser.
The following example is available:
Solution / Fix
Invision Power Board 'Signature' iFrame Security Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Invision Power Board 'Signature' iFrame Security Vulnerability
References:
References:
- Invision Power Board Home Page (Invision Power Services)
- Invision Power Board <=2.3.x iFrame Vuln ([email protected])