PT-2005-2896 · Invision · Invision Blog

James Bercegay

·

Publicado

2005-06-09

·

Atualizado

2016-10-18

·

CVE-2005-1945

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Invision Blog versions prior to 1.1.2 Final
Description A cross-site scripting issue exists due to a vulnerability in the convert highlite words function. This allows remote attackers to inject arbitrary web script or HTML via double hex encoded highlight data.
Recommendations For versions prior to 1.1.2 Final, update to version 1.1.2 Final or later to resolve the issue. As a temporary workaround, consider disabling the convert highlite words function until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-1945

Produtos afetados

Invision Blog