4.3
CVSSv2

CVE-2005-0477

Published: 30/03/2005 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the SML code for Invision Power Board 1.3.1 FINAL allows remote malicious users to inject arbitrary web script via (1) a signature file or (2) a message post containing an IMG tag within a COLOR tag whose style is set to background:url.

Vulnerable Product Search on Vulmon Subscribe to Product

invision power services invision power board 1.3

invision power services invision power board 1.3.1_final

invision power services invision power board 1.1.2

invision power services invision power board 1.2

invision power services invision power board 1.0

invision power services invision power board 1.3_final

invision power services invision power board 1.0.1

invision power services invision power board 1.1.1

Exploits

source: wwwsecurityfocuscom/bid/12607/info Invision Power Board is reported prone to a JavaScript injection vulnerability It is reported that the SML Code 'COLOR' tag is not sufficiently sanitized of malicious script content Since this could permit an attacker to inject hostile JavaScript into the forum system, it is possible to steal ...