Invision Power Board Index.php Showtopic Cross-Site Scripting Vulnerability
BID:8575
Info
Invision Power Board Index.php Showtopic Cross-Site Scripting Vulnerability
| Bugtraq ID: | 8575 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 09 2003 12:00AM |
| Updated: | Sep 09 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to Boy Bear <[email protected]>. |
| Vulnerable: |
Invision Power Services Invision Board 1.3 Final Invision Power Services Invision Board 1.3 Invision Power Services Invision Board 1.2 Invision Power Services Invision Board 1.1.2 Invision Power Services Invision Board 1.1.1 Invision Power Services Invision Board 1.0.1 Invision Power Services Invision Board 1.0 |
| Not Vulnerable: | |
Discussion
Invision Power Board Index.php Showtopic Cross-Site Scripting Vulnerability
Invision Power Board is prone to a cross-site scripting vulnerability. It has been reported that a remote attacker may construct a malicious link to the index.php script and supply arbitrary HTML code as a value for the 'showtopic' URI parameter. If this link is followed, the content of the URI parameter will be rendered in the browser of the user who followed the link.
Invision Power Board is prone to a cross-site scripting vulnerability. It has been reported that a remote attacker may construct a malicious link to the index.php script and supply arbitrary HTML code as a value for the 'showtopic' URI parameter. If this link is followed, the content of the URI parameter will be rendered in the browser of the user who followed the link.
Solution / Fix
Invision Power Board Index.php Showtopic Cross-Site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.