CVE-2008-0913: XSS
Published Feb 22, 2008
·Updated
Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB or IP.Board) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via crafted BBCodes in an unspecified context.
Affected Software
1 affected component
Invision Power Services Invision Power Board=2.3.4
Remediation
Patch Available
Event History
Feb 22, 2008
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0913?
CVE-2008-0913 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2008-0913?
To fix CVE-2008-0913, upgrade to a version of Invision Power Board that is not vulnerable, specifically versions later than 2.3.4.
3
What type of vulnerability is CVE-2008-0913?
CVE-2008-0913 is a cross-site scripting (XSS) vulnerability that allows for the injection of arbitrary web scripts or HTML.
4
Who is affected by CVE-2008-0913?
CVE-2008-0913 affects users running Invision Power Board version 2.3.4.
5
Can CVE-2008-0913 be exploited remotely?
Yes, CVE-2008-0913 can be exploited remotely by attackers through crafted BBCodes.