First published: Fri Mar 13 2020(Updated: )
Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt attachment.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Invisioncommunity Invision Power Board | >=2.0<=3.0.4 | |
Microsoft Internet Explorer | =5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this security issue is CVE-2009-5159.
The affected software for this vulnerability is Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4 when Internet Explorer 5 is used.
The severity of CVE-2009-5159 is medium with a CVSS score of 6.1.
This vulnerability exploits XSS through a .txt attachment when using Internet Explorer 5.
You can find more information about this vulnerability at the following references: [https://www.securityfocus.com/bid/37263/info](https://www.securityfocus.com/bid/37263/info), [https://www.exploit-db.com/exploits/33394](https://www.exploit-db.com/exploits/33394), [https://packetstormsecurity.com/files/83624/Invision-Power-Board-3.0.4-Cross-Site-Scripting.html](https://packetstormsecurity.com/files/83624/Invision-Power-Board-3.0.4-Cross-Site-Scripting.html).