PT-2004-1513 · Invision · Invision Power Board

Rafel Ivgi

+1

·

Published

2004-03-18

·

Updated

2017-07-11

·

CVE-2004-0359

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Invision Power Board version 1.3
Description A cross-site scripting (XSS) issue exists, allowing remote attackers to execute arbitrary scripts as other users. This is achieved by manipulating specific parameters in the index.php file, including the c, f, showtopic, showuser, or username parameters.
Recommendations For Invision Power Board version 1.3, as a temporary workaround, consider restricting access to the index.php file until a patch is available. Avoid using the parameters c, f, showtopic, showuser, or username in the index.php file until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0359

Affected Products

Invision Power Board