Invision Board Overlapping IBF Formatting Tag HTML Injection Vulnerability
BID:8335
Info
Invision Board Overlapping IBF Formatting Tag HTML Injection Vulnerability
| Bugtraq ID: | 8335 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 04 2003 12:00AM |
| Updated: | Aug 04 2003 12:00AM |
| Credit: | Discovery is credited to Daniel Boland <[email protected]>. |
| Vulnerable: |
Invision Power Services Invision Board 1.2 Invision Power Services Invision Board 1.1.2 Invision Power Services Invision Board 1.1.1 Invision Power Services Invision Board 1.0.1 Invision Power Services Invision Board 1.0 |
| Not Vulnerable: | |
Discussion
Invision Board Overlapping IBF Formatting Tag HTML Injection Vulnerability
It may be possible to inject hostile HTML script code into Invision Board by using overlapping IBF formatting tags. This could cause the hostile code to be interpreted in the context of the site hosting the software. Any input fields which support inclusion of IBF code may be prone to this issue.
It should be noted that it may not be possible to inject arbitrary HTML into Invision Board but it is more likely that this could be exploited to spoof or manipulate links or include other abusive content.
It may be possible to inject hostile HTML script code into Invision Board by using overlapping IBF formatting tags. This could cause the hostile code to be interpreted in the context of the site hosting the software. Any input fields which support inclusion of IBF code may be prone to this issue.
It should be noted that it may not be possible to inject arbitrary HTML into Invision Board but it is more likely that this could be exploited to spoof or manipulate links or include other abusive content.
Exploit / POC
Invision Board Overlapping IBF Formatting Tag HTML Injection Vulnerability
This may be exploited with a web browser.
This may be exploited with a web browser.
Solution / Fix
Invision Board Overlapping IBF Formatting Tag HTML Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Invision Board Overlapping IBF Formatting Tag HTML Injection Vulnerability
References:
References:
- Invision Board Homepage (Invision Power Services)
- Invision Board spoof and defacement (Daniel Boland
)