First published: Mon May 16 2005(Updated: )
Cross-site scripting (XSS) vulnerability in (1) search.php and (2) topics.php for Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the highlite parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Invisioncommunity Invision Power Board | =1.0 | |
Invisioncommunity Invision Power Board | =1.0.1 | |
Invisioncommunity Invision Power Board | =1.1.1 | |
Invisioncommunity Invision Power Board | =1.1.2 | |
Invisioncommunity Invision Power Board | =1.2 | |
Invisioncommunity Invision Power Board | =1.3 | |
Invisioncommunity Invision Power Board | =2.0_alpha_3 | |
Invisioncommunity Invision Power Board | =2.0_pdr3 | |
Invision Power Board | =2.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1597 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
To fix CVE-2005-1597, upgrade your Invision Power Board to version 2.0.4 or later.
CVE-2005-1597 affects Invision Power Board versions 1.0 through 2.0.3.
Yes, CVE-2005-1597 can be exploited remotely by attackers using crafted URLs.
CVE-2005-1597 allows attackers to inject arbitrary web scripts or HTML.