First published: Thu Mar 18 2004(Updated: )
Cross-site scripting (XSS) vulnerability in index.php for Invision Power Board 1.3 final allows remote attackers to execute arbitrary script as other users via the (1) c, (2) f, (3) showtopic, (4) showuser, or (5) username parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Invisioncommunity Invision Power Board | =1.3.1_final | |
Invisioncommunity Invision Power Board | =1.3_final |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0359 is considered a high severity vulnerability due to its potential for exploitation via cross-site scripting.
CVE-2004-0359 affects Invision Power Board versions 1.3 and 1.3.1 final.
To fix CVE-2004-0359, upgrade your Invision Power Board to a version that is patched for this XSS vulnerability.
CVE-2004-0359 allows remote attackers to execute arbitrary scripts as other users via specific parameters.
Yes, CVE-2004-0359 can be exploited without user interaction, making it particularly dangerous.