Vulnerabilities > CVE-2006-5204 - Cross-Site Scripting vulnerability in Invision Power Board

047910
CVSS 2.1 - LOW
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
SINGLE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
high complexity
invision-power-services

Summary

Cross-site scripting (XSS) vulnerability in action_admin/member.php in Invision Power Board (IPB) 2.1.7 and earlier allows remote authenticated users to inject arbitrary web script or HTML via a reference to a script in the avatar setting, which can be leveraged for a cross-site request forgery (CSRF) attack involving forced SQL execution by an admin. An update for that addressed this vulnerability is available on the Invision Power Services web site. The following requirements must be met for this attack to take place: - The database table prefix must be known - The admin must have access to the SQL Toolbox (any "root admin") - The admin must have images and referers turned on in their browser, and their browser must follow Location headers (default behaviour for most browsers) - The admin must view a malicious script as an image in their browser

Vulnerable Configurations

Part Description Count
Application
Invision_Power_Services
36