PT-2004-3174 · Invision · Invision Power Board

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-2279

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Invision Power Board version 1.3 Final
Description: A cross-site scripting (XSS) issue allows remote attackers to execute arbitrary script as other users. This is achieved by exploiting the pop parameter in a chat action to the "index.php" endpoint.
Recommendations: For Invision Power Board version 1.3 Final, consider restricting access to the pop parameter in the chat action to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-2279

Affected Products

Invision Power Board