CVE-2005-1443: XSS
Published May 3, 2005
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in index.php for Invision Power Board (IPB) 2.0.3 and 2.1 Alpha 2 allows remote attackers to inject arbitrary web script or HTML via the (1) act, (2) Members, (3) calendar, or (4) HID parameters.
Affected Software
4 affected components
Invision Power Services Invision Power Board=2.1_alpha2
Invision Power Services Invision Power Board=2.0.3
Invision Power Services Invision Power Board=2.0.3
Invision Power Services Invision Power Board=2.1_alpha2
Event History
May 3, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1443?
CVE-2005-1443 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2005-1443?
To fix CVE-2005-1443, ensure you upgrade Invision Power Board to the latest version that addresses these vulnerabilities.
3
What software versions are affected by CVE-2005-1443?
CVE-2005-1443 affects Invision Power Board versions 2.0.3 and 2.1 Alpha 2.
4
What are the potential impacts of CVE-2005-1443?
The potential impacts of CVE-2005-1443 include unauthorized script execution and data theft.
5
Who can exploit CVE-2005-1443?
CVE-2005-1443 can be exploited by remote attackers who can inject scripts via specific parameters.