CVE-2006-7064: XSS
Cross-site scripting (XSS) vulnerability in forum/admin.php for Invision Power Board (IPB) 2.1.6 and earlier allows remote attackers to inject arbitrary web script or HTML as the administrator via the phpinfo parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-7064?
CVE-2006-7064 is classified as a medium severity vulnerability due to its ability to exploit administrator privileges via XSS.
How do I fix CVE-2006-7064?
To fix CVE-2006-7064, it is recommended to upgrade to a version of Invision Power Board that is not vulnerable, specifically versions after 2.1.6.
Which versions are affected by CVE-2006-7064?
CVE-2006-7064 affects Invision Power Board versions up to and including 2.1.6.
What type of attack is associated with CVE-2006-7064?
CVE-2006-7064 is associated with cross-site scripting (XSS) attacks that allow remote attackers to inject arbitrary web scripts or HTML.
Can CVE-2006-7064 affect a website's security?
Yes, CVE-2006-7064 can significantly compromise a website's security by allowing attackers to exploit administrative functionalities.