CVE-2008-1359: XSS
Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB or IP.Board) 2.3.4 before 2008-03-13 allows remote attackers to inject arbitrary web script or HTML via nested BBCodes, a different vector than CVE-2008-0913.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1359?
CVE-2008-1359 is considered a moderate severity XSS vulnerability that can allow attackers to inject scripts into web pages.
How do I fix CVE-2008-1359?
To fix CVE-2008-1359, you should update your Invision Power Board to a version released after March 13, 2008.
What versions of Invision Power Board are affected by CVE-2008-1359?
CVE-2008-1359 affects all versions of Invision Power Board up to and including 2.3.4.
Can CVE-2008-1359 lead to account compromise?
Yes, CVE-2008-1359 can enable attackers to perform actions on behalf of users by executing malicious scripts.
What impact can CVE-2008-1359 have on users?
The impact of CVE-2008-1359 includes potential data theft, session hijacking, and other malicious activities through the injected scripts.