Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Invision Power Board User Profile And Subscription Manager Multiple Input Validation Vulnerabilities

Invision Power Board (IP.Board) is prone to multiple input-validation vulnerabilities because it fails to adequately sanitize user-supplied input.

Attackers can exploit these issues to inject arbitrary script code into a user profile or to modify the privileges of arbitrary user accounts. Injected code will be stored persistently on the affected site.

IP.Board 2.3.1 is vulnerable; other versions may also be affected.







 

Privacy Statement
Copyright 2009, SecurityFocus