CVE-2014-5106: XSS
Published Jul 28, 2014
·Updated
Cross-site scripting (XSS) vulnerability in Invision Power IP.Board (aka IPB or Power Board) 3.4.x through 3.4.6 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header to admin/install/index.php.
Affected Software
13 affected components
Invisioncommunity Invision Power Board=3.4.0
Invisioncommunity Invision Power Board=3.4.0-alpha1
Invisioncommunity Invision Power Board=3.4.0-beta1
Invisioncommunity Invision Power Board=3.4.0-beta2
Invisioncommunity Invision Power Board=3.4.0-beta3
Invisioncommunity Invision Power Board=3.4.0-beta4
Invisioncommunity Invision Power Board=3.4.0-beta5
Invisioncommunity Invision Power Board=3.4.1
Invisioncommunity Invision Power Board=3.4.2
Invisioncommunity Invision Power Board=3.4.3
Invisioncommunity Invision Power Board=3.4.4
Invisioncommunity Invision Power Board=3.4.5
Invisioncommunity Invision Power Board=3.4.6
Event History
Jul 28, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5106?
CVE-2014-5106 has a medium severity rating due to its potential to allow remote attackers to inject malicious scripts.
2
How do I fix CVE-2014-5106?
To fix CVE-2014-5106, upgrade Invision Power Board to a version later than 3.4.6.
3
What versions of Invision Power Board are affected by CVE-2014-5106?
CVE-2014-5106 affects Invision Power Board versions 3.4.0 through 3.4.6.
4
What type of vulnerability is CVE-2014-5106?
CVE-2014-5106 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2014-5106 be exploited through user input?
Yes, CVE-2014-5106 can be exploited via injection through the HTTP Referer header.