CVE-2007-4912: XSS
Cross-site scripting (XSS) vulnerability in ipskernel/classajax.php in Invision Power Board (IPB or IP.Board) 2.3.1 up to 20070912 allows remote attackers to inject arbitrary web script or HTML into user profile fields via unspecified vectors related to character sets other than iso-8859-1 or utf-8.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4912?
CVE-2007-4912 is classified as a moderate severity cross-site scripting vulnerability.
How do I fix CVE-2007-4912?
To fix CVE-2007-4912, upgrade to a patched version of Invision Power Board, preferably newer than the affected versions.
What are the affected versions regarding CVE-2007-4912?
CVE-2007-4912 affects Invision Power Board versions 2.1.5 to 2.3.1 including specific sub-versions listed.
How does CVE-2007-4912 impact users?
CVE-2007-4912 allows remote attackers to inject arbitrary scripts into user profiles, potentially leading to session hijacking or malicious content execution.
What type of vulnerability is CVE-2007-4912?
CVE-2007-4912 is a cross-site scripting (XSS) vulnerability that can lead to security breaches if exploited.