First published: Fri Apr 18 2008(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Redirect parameter to login.asp and the (2) OrderBy parameter to member_send.asp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Invision Community | <=2.4 | |
Invision Community | =1.0 | |
Invision Community | =1.1 | |
Invision Community | =2.1 | |
Invision Community | =2.2 | |
Invision Community | =2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1896 has a moderate severity rating due to its impact on user data and the potential for exploitation.
To fix CVE-2008-1896, you should update Carbon Communities to version 2.5 or later, which addresses the XSS vulnerabilities.
CVE-2008-1896 affects Carbon Communities versions 2.4 and earlier, including versions 1.0, 1.1, 2.1, 2.2, and 2.3.
CVE-2008-1896 allows attackers to perform cross-site scripting (XSS) attacks by injecting arbitrary web scripts via vulnerable parameters.
Users and organizations utilizing Carbon Communities versions 2.4 and earlier are impacted by CVE-2008-1896.