Korean
<< Back
VID 21533
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The Invision Power Board, according to its version number, has an HTML injection vulnerability. Invision Power Board is a PHP-based Web forum software package, distributed by Invision Power Services, Inc. Invision Power Board 2.0.2 and earlier could allow to a remote attacker to inject a malicious IFRAME through an HTTP POST request, due to a lack of filtering of HTML tags. This vulnerability could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If this link were to be followed, the hostile code may be rendered in the web browser of the victim user. This would occur in the security context of the affected web site and may allow for theft of cookie-based authentication credentials or other attacks.

* Note: This check solely relied on the version number of the Invision Power Board installed on the remote web server to assess this vulnerability, so this might be a false positive.

* Platforms Affected:
Invision Power Board 2.0.2 and earlier
Any Operating system Any version
Recommendation Upgrade to the latest version of Invision Power Board (2.0.3 or later), available from the Invision Power Board Web site at http://www.invisionboard.com
Related URL CVE-2005-0886 (CVE)
Related URL 12888 (SecurityFocus)
Related URL (ISS)