Vulnerabilities > CVE-2005-1443 - Cross-Site Scripting vulnerability in Invision Power Board

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
invision-power-services
nessus

Summary

Multiple cross-site scripting (XSS) vulnerabilities in index.php for Invision Power Board (IPB) 2.0.3 and 2.1 Alpha 2 allows remote attackers to inject arbitrary web script or HTML via the (1) act, (2) Members, (3) calendar, or (4) HID parameters.

Nessus

NASL familyCGI abuses : XSS
NASL idINVISION_POWER_BOARD_ACT_XSS.NASL
descriptionThe version of Invision Power Board installed on the remote host suffers from a cross-site scripting vulnerability due to its failure to sanitize user input via the
last seen2020-06-01
modified2020-06-02
plugin id18201
published2005-05-05
reporterThis script is Copyright (C) 2005-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/18201
titleInvision Power Board index.php Multiple Parameter XSS