vendor:
Invision Power Board
by:
SecurityFocus
7.5
CVSS
HIGH
JavaScript Injection
79
CWE
Product Name: Invision Power Board
Affected Version From: 1.3.2001
Affected Version To: 2.0.3
Patch Exists: YES
Related CWE: N/A
CPE: a:invision_power_services:invision_power_board
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2005
Invision Power Board JavaScript Injection Vulnerability
Invision Power Board is reported prone to a JavaScript injection vulnerability. It is reported that the SML Code 'COLOR' tag is not sufficiently sanitized of malicious script content. Since this could permit an attacker to inject hostile JavaScript into the forum system, it is possible to steal cookie credentials or misrepresent site content.
Mitigation:
Input validation should be used to ensure that user-supplied data is properly sanitized before being used in the application.