CVE-2007-2963: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Invision Power Board (IPB or IP.Board) 2.2.2, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via (1) modulebbcodeloader.php, (2) modulediv.php, (3) moduleemail.php, (4) moduleimage.php, (5) modulelink.php, or (6) the editorid parameter to moduletable.php in jscripts/folderrtefiles/. NOTE: some details were obtained from third party sources.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2963?
CVE-2007-2963 has been classified as a high severity vulnerability due to its potential for remote exploitation via cross-site scripting.
How do I fix CVE-2007-2963?
To fix CVE-2007-2963, you should update Invision Power Board to version 2.2.3 or later, which addresses these vulnerabilities.
What types of attacks does CVE-2007-2963 enable?
CVE-2007-2963 enables attackers to perform cross-site scripting attacks, allowing them to inject arbitrary web scripts or HTML into affected pages.
Which versions of Invision Power Board are affected by CVE-2007-2963?
CVE-2007-2963 affects Invision Power Board version 2.2.2 and possibly earlier versions.
Can CVE-2007-2963 be exploited without user interaction?
Yes, CVE-2007-2963 can be exploited without user interaction, making it particularly dangerous for users visiting compromised sites.