CVE-2008-6565: XSS
Published Mar 31, 2009
·Updated
Cross-site scripting (XSS) vulnerability in Invision Power Board 2.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via an IFRAME tag in the signature.
Affected Software
43 affected components
Invision Power Services Invision Power Board=2.0_pf1
Invision Power Services Invision Power Board=2.2
Invision Power Services Invision Power Board=2.1_beta2
Invision Power Services Invision Power Board=1.0
Invision Power Services Invision Power Board=1.1.2
Invision Power Services Invision Power Board=2.0.4
Invision Power Services Invision Power Board=2.2.2
Invision Power Services Invision Power Board=2.1_rc1
Invision Power Services Invision Power Board=2.1.1
Invision Power Services Invision Power Board=2.1.6
Invision Power Services Invision Power Board=2.1_alpha2
Invision Power Services Invision Power Board=2.0_alpha3
Invision Power Services Invision Power Board=1.1.1
Invision Power Services Invision Power Board=2.1.5_2006-03-08
Invision Power Services Invision Power Board=2.1.2
Invision Power Services Invision Power Board=2.1.3
Invision Power Services Invision Power Board=1.0.3
Invision Power Services Invision Power Board=2.0_pdr3
Invision Power Services Invision Power Board=2.0
Invision Power Services Invision Power Board=2.1_beta5
Invision Power Services Invision Power Board=1.3_final
Invision Power Services Invision Power Board=2.1.0
Invision Power Services Invision Power Board=1.2
Invision Power Services Invision Power Board=2.1.5
Invision Power Services Invision Power Board=2.0.0
Invision Power Services Invision Power Board=2.1.5_2006-04-25
Invision Power Services Invision Power Board=1.0.1
Invision Power Services Invision Power Board=2.2.1
Invision Power Services Invision Power Board=2.0.3
Invision Power Services Invision Power Board=2.1_beta4
Invision Power Services Invision Power Board=2.1
Invision Power Services Invision Power Board=2.1_beta3
Invision Power Services Invision Power Board=2.1.4
Invision Power Services Invision Power Board=1.3.1_final
Invision Power Services Invision Power Board=2.1.7
Invision Power Services Invision Power Board=2.0_pf2
Invision Power Services Invision Power Board=2.0.2
Invision Power Services Invision Power Board<=2.3.1
Invision Power Services Invision Power Board=2.0.1
Invision Power Services Invision Power Board=2.3
Invision Power Services Invision Power Board=1.3
Invision Power Services Invision Power Board=2.0.x
Invision Power Services Invision Power Board=2.1.x
Event History
Mar 31, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-6565?
CVE-2008-6565 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2008-6565?
To fix CVE-2008-6565, upgrade to a version of Invision Power Board later than 2.3.1 where the vulnerability has been patched.
3
What type of attack does CVE-2008-6565 enable?
CVE-2008-6565 enables remote attackers to perform cross-site scripting (XSS) attacks by injecting arbitrary web scripts or HTML.
4
Which versions of Invision Power Board are affected by CVE-2008-6565?
CVE-2008-6565 affects Invision Power Board versions 2.3.1 and earlier.
5
Can CVE-2008-6565 be exploited without authentication?
Yes, CVE-2008-6565 can be exploited by unauthenticated attackers, making it a significant risk.