PT-2004-1513 · Invision · Invision Power Board

Rafel Ivgi

+1

·

Publicado

2004-03-18

·

Atualizado

2017-07-11

·

CVE-2004-0359

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Invision Power Board version 1.3
Description A cross-site scripting (XSS) issue exists, allowing remote attackers to execute arbitrary scripts as other users. This is achieved by manipulating specific parameters in the index.php file, including the c, f, showtopic, showuser, or username parameters.
Recommendations For Invision Power Board version 1.3, as a temporary workaround, consider restricting access to the index.php file until a patch is available. Avoid using the parameters c, f, showtopic, showuser, or username in the index.php file until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-0359

Produtos afetados

Invision Power Board