CVE-2004-2279: XSS
Published Dec 31, 2004
·Updated
Cross-site scripting (XSS) vulnerability in Invision Power Board 1.3 Final allows remote attackers to execute arbitrary script as other users via the pop parameter in a chat action to index.php.
Affected Software
1 affected component
Invision Power Services Invision Power Board=1.3_final
Event History
Dec 31, 2004
CVE Published
05:00 AM
Jul 19, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2279?
CVE-2004-2279 is considered to have a moderate severity level due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2004-2279?
To fix CVE-2004-2279, upgrade Invision Power Board to a version that has addressed the XSS vulnerability.
3
What is the main cause of CVE-2004-2279?
The main cause of CVE-2004-2279 is inadequate input validation of the 'pop' parameter in the chat action of index.php.
4
Who is affected by CVE-2004-2279?
CVE-2004-2279 affects users of Invision Power Board version 1.3 Final.
5
Can CVE-2004-2279 be exploited remotely?
Yes, CVE-2004-2279 can be exploited remotely by attackers to execute arbitrary scripts as other users.