First published: Wed Aug 10 2005(Updated: )
Invision Power Board (IPB) 1.0.3 allows remote attackers to inject arbitrary web script or HTML via an attachment, which is automatically downloaded and processed as HTML.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Invisioncommunity Invision Power Board | =2.0 | |
Invisioncommunity Invision Power Board | =2.0.1 | |
Invisioncommunity Invision Power Board | =2.0.2 | |
Invisioncommunity Invision Power Board | =2.0.3 | |
Invisioncommunity Invision Power Board | =2.0.4 | |
Invisioncommunity Invision Power Board | =2.0_alpha_3 | |
Invisioncommunity Invision Power Board | =2.0_pdr3 | |
Invisioncommunity Invision Power Board | =2.0_pf1 | |
Invisioncommunity Invision Power Board | =2.0_pf2 | |
Invisioncommunity Invision Power Board | =2.1_alpha2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2542 is considered a medium severity vulnerability due to its potential for remote code execution through script injection.
To mitigate CVE-2005-2542, upgrade Invision Power Board to the latest version that addresses this security issue.
CVE-2005-2542 affects users of Invision Power Board versions 1.0.3 through 2.0.4 and various alpha and beta releases.
Attackers exploiting CVE-2005-2542 can inject arbitrary web scripts or HTML, potentially compromising the security of the affected systems.
Disabling attachment upload features can act as a temporary workaround for CVE-2005-2542 until a patch is applied.