CVE-2005-1597: XSS
Published May 16, 2005
·Updated
Cross-site scripting (XSS) vulnerability in (1) search.php and (2) topics.php for Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the highlite parameter.
Affected Software
9 affected components
Invision Power Services Invision Board=2.0_pdr3
Invision Power Services Invision Board=1.3
Invision Power Services Invision Board=1.1.1
Invision Power Services Invision Board=1.2
Invision Power Services Invision Board=1.0
Invision Power Services Invision Power Board=2.0.3
Invision Power Services Invision Board=2.0_alpha_3
Invision Power Services Invision Board=1.1.2
Invision Power Services Invision Board=1.0.1
Remediation
Patch Available
Event History
May 16, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1597?
CVE-2005-1597 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2005-1597?
To fix CVE-2005-1597, upgrade your Invision Power Board to version 2.0.4 or later.
3
What versions are affected by CVE-2005-1597?
CVE-2005-1597 affects Invision Power Board versions 1.0 through 2.0.3.
4
Can CVE-2005-1597 be exploited remotely?
Yes, CVE-2005-1597 can be exploited remotely by attackers using crafted URLs.
5
What types of scripts can be injected through CVE-2005-1597?
CVE-2005-1597 allows attackers to inject arbitrary web scripts or HTML.