PT-2005-2896 · Invision · Invision Blog

James Bercegay

·

Published

2005-06-09

·

Updated

2016-10-18

·

CVE-2005-1945

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Invision Blog versions prior to 1.1.2 Final
Description A cross-site scripting issue exists due to a vulnerability in the convert highlite words function. This allows remote attackers to inject arbitrary web script or HTML via double hex encoded highlight data.
Recommendations For versions prior to 1.1.2 Final, update to version 1.1.2 Final or later to resolve the issue. As a temporary workaround, consider disabling the convert highlite words function until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1945

Affected Products

Invision Blog