CVE-2006-5204: XSS
Cross-site scripting (XSS) vulnerability in actionadmin/member.php in Invision Power Board (IPB) 2.1.7 and earlier allows remote authenticated users to inject arbitrary web script or HTML via a reference to a script in the avatar setting, which can be leveraged for a cross-site request forgery (CSRF) attack involving forced SQL execution by an admin.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5204?
CVE-2006-5204 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2006-5204?
To fix CVE-2006-5204, upgrade Invision Power Board to version 2.1.8 or later, which addresses the vulnerability.
Who is affected by CVE-2006-5204?
CVE-2006-5204 affects remote authenticated users of Invision Power Board versions 2.1.7 and earlier.
What can attackers exploit with CVE-2006-5204?
Attackers can exploit CVE-2006-5204 to inject arbitrary web scripts or HTML through the avatar setting.
What type of vulnerability is CVE-2006-5204?
CVE-2006-5204 is a cross-site scripting (XSS) vulnerability.