Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.1.5 and earlier before 20060308 allows remote attackers to inject arbitrary web script or HTML via a Private Message (PM) in certain circumstances.
Link | Tags |
---|---|
http://secunia.com/advisories/19299 | third party advisory vendor advisory |
http://forums.invisionpower.com/index.php?showtopic=209178 | |
http://www.vupen.com/english/advisories/2006/1044 | vdb entry |
http://www.securityfocus.com/bid/17187 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/25384 | vdb entry |