CVE-2006-3197: XSS
Published Jun 23, 2006
·Updated
Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.1.6 and earlier allows remote attackers to inject arbitrary web script or HTML via a POST that contains hexadecimal-encoded HTML.
Affected Software
14 affected components
Invision Power Services Invision Power Board=2.1_beta2
Invision Power Services Invision Power Board=2.1_rc1
Invision Power Services Invision Power Board=2.1.1
Invision Power Services Invision Power Board=2.1.6
Invision Power Services Invision Power Board=2.1_alpha2
Invision Power Services Invision Power Board=2.1.2
Invision Power Services Invision Power Board=2.1.3
Invision Power Services Invision Power Board=2.1_beta5
Invision Power Services Invision Power Board=2.1.0
Invision Power Services Invision Power Board=2.1.5
Invision Power Services Invision Power Board=2.1_beta4
Invision Power Services Invision Power Board=2.1
Invision Power Services Invision Power Board=2.1_beta3
Invision Power Services Invision Power Board=2.1.4
Remediation
Patch Available
Patch Available
Event History
Jun 23, 2006
CVE Published
12:02 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-3197?
CVE-2006-3197 is considered a moderate severity vulnerability due to its ability to allow cross-site scripting attacks.
2
How do I fix CVE-2006-3197?
To fix CVE-2006-3197, upgrade Invision Power Board to a version later than 2.1.6.
3
What are the affected versions for CVE-2006-3197?
CVE-2006-3197 affects Invision Power Board versions 2.1.6 and earlier.
4
What type of vulnerability is CVE-2006-3197?
CVE-2006-3197 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2006-3197 be exploited remotely?
Yes, CVE-2006-3197 can be exploited remotely by attackers injecting arbitrary web scripts via HTTP POST.