First published: Tue May 03 2005(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in index.php for Invision Power Board (IPB) 2.0.3 and 2.1 Alpha 2 allows remote attackers to inject arbitrary web script or HTML via the (1) act, (2) Members, (3) calendar, or (4) HID parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Invision Power Board | =2.1_alpha2 | |
Invision Power Board | =2.0.3 | |
Invision Power Board | =2.0.3 | |
Invision Power Board | =2.1_alpha2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1443 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2005-1443, ensure you upgrade Invision Power Board to the latest version that addresses these vulnerabilities.
CVE-2005-1443 affects Invision Power Board versions 2.0.3 and 2.1 Alpha 2.
The potential impacts of CVE-2005-1443 include unauthorized script execution and data theft.
CVE-2005-1443 can be exploited by remote attackers who can inject scripts via specific parameters.