PT-2004-3174 · Invision · Invision Power Board

Publicado

2004-12-31

·

Atualizado

2017-07-11

·

CVE-2004-2279

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Invision Power Board version 1.3 Final
Description: A cross-site scripting (XSS) issue allows remote attackers to execute arbitrary script as other users. This is achieved by exploiting the pop parameter in a chat action to the "index.php" endpoint.
Recommendations: For Invision Power Board version 1.3 Final, consider restricting access to the pop parameter in the chat action to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-2279

Produtos afetados

Invision Power Board