CVE-2004-0359: XSS
Published Mar 18, 2004
·Updated
Cross-site scripting (XSS) vulnerability in index.php for Invision Power Board 1.3 final allows remote attackers to execute arbitrary script as other users via the (1) c, (2) f, (3) showtopic, (4) showuser, or (5) username parameters.
Affected Software
2 affected components
Invision Power Services Invision Board=1.3.1_final
Invision Power Services Invision Board=1.3_final
Event History
Mar 18, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0359?
CVE-2004-0359 is considered a high severity vulnerability due to its potential for exploitation via cross-site scripting.
2
What systems are affected by CVE-2004-0359?
CVE-2004-0359 affects Invision Power Board versions 1.3 and 1.3.1 final.
3
How do I fix CVE-2004-0359?
To fix CVE-2004-0359, upgrade your Invision Power Board to a version that is patched for this XSS vulnerability.
4
What type of attack does CVE-2004-0359 allow?
CVE-2004-0359 allows remote attackers to execute arbitrary scripts as other users via specific parameters.
5
Can CVE-2004-0359 be exploited without user interaction?
Yes, CVE-2004-0359 can be exploited without user interaction, making it particularly dangerous.