Cross-site scripting (XSS) vulnerability in Invision Power Board (IP.Board) 2.1.x and 2.2.x allows remote attackers to inject arbitrary web script or HTML by uploading crafted images or PDF files.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:30
Type | Values Removed | Values Added |
---|---|---|
References | () http://forums.invisionpower.com/index.php?showtopic=234377 - Patch | |
References | () http://osvdb.org/35427 - | |
References | () http://secunia.com/advisories/25021 - Patch, Vendor Advisory | |
References | () http://www.vupen.com/english/advisories/2007/1558 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/33942 - |
Information
Published : 2007-04-30 22:19
Updated : 2024-11-21 00:30
NVD link : CVE-2007-2349
Mitre link : CVE-2007-2349
CVE.ORG link : CVE-2007-2349
JSON object : View
Products Affected
invision_power_services
- invision_power_board
CWE