Cross-site scripting (XSS) vulnerability in the SML code for Invision Power Board 1.3.1 FINAL allows remote malicious users to inject arbitrary web script via (1) a signature file or (2) a message post containing an IMG tag within a COLOR tag whose style is set to background:url.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
invision power services invision power board 1.3 |
||
invision power services invision power board 1.3.1_final |
||
invision power services invision power board 1.1.2 |
||
invision power services invision power board 1.2 |
||
invision power services invision power board 1.0 |
||
invision power services invision power board 1.3_final |
||
invision power services invision power board 1.0.1 |
||
invision power services invision power board 1.1.1 |