CVE-2005-1945: XSS
Cross-site scripting (XSS) vulnerability in the converthighlitewords function in Invision Blog before 1.1.2 Final allows remote attackers to inject arbitrary web script or HTML via double hex encoded highlight data.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2005-1945?
CVE-2005-1945 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How does CVE-2005-1945 work?
CVE-2005-1945 allows attackers to inject arbitrary web scripts or HTML through the convert_highlite_words function by exploiting double hex encoded highlight data.
Which versions of Invision Blog are affected by CVE-2005-1945?
CVE-2005-1945 affects Invision Blog versions 1.0 and 1.1 before the 1.1.2 Final release.
How do I fix CVE-2005-1945?
To fix CVE-2005-1945, upgrade Invision Blog to version 1.1.2 Final or later.
Can CVE-2005-1945 be exploited remotely?
Yes, CVE-2005-1945 can be exploited remotely, allowing attackers to execute scripts in the context of a victim's session.