CVE-2005-0886: XSS
Published Mar 26, 2005
·Updated
Cross-site scripting (XSS) vulnerability in Invision Power Board 2.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an HTTP POST request.
Affected Software
15 affected components
Invision Power Services Invision Board=1.0
Invision Power Services Invision Board=1.0.1
Invision Power Services Invision Board=1.1.1
Invision Power Services Invision Board=1.1.2
Invision Power Services Invision Board=1.2
Invision Power Services Invision Board=1.3
Invision Power Services Invision Board=1.3.1_final
Invision Power Services Invision Board=1.3_final
Invision Power Services Invision Board=2.0
Invision Power Services Invision Board=2.0.1
Invision Power Services Invision Board=2.0.2
Invision Power Services Invision Board=2.0_alpha_3
Invision Power Services Invision Board=2.0_pdr3
Invision Power Services Invision Board=2.0_pf1
Invision Power Services Invision Board=2.0_pf2
Event History
Mar 26, 2005
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0886?
CVE-2005-0886 is classified as a moderate severity vulnerability due to the potential for cross-site scripting attacks.
2
How do I fix CVE-2005-0886?
To fix CVE-2005-0886, upgrade to a version of Invision Power Board that is higher than 2.0.2.
3
What types of attacks can exploit CVE-2005-0886?
CVE-2005-0886 can be exploited through cross-site scripting attacks, allowing attackers to inject arbitrary web scripts.
4
Which versions of Invision Power Board are affected by CVE-2005-0886?
Invision Power Board versions 2.0.2 and earlier are affected by CVE-2005-0886.
5
Can I identify CVE-2005-0886 on my server?
Yes, you can identify CVE-2005-0886 on your server by checking the version of the Invision Power Board software currently installed.