AlphaOne Technology Support Forums
Welcome, Guest. Please login or register.
December 02, 2008, 12:34:41 PM

Login with username, password and session length
Search:     Advanced search
1733 Posts in 827 Topics by 4756 Members
Latest Member: Uobeley
* Home Help Search Login Register
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Security Announcements  |  Invisionboard  |  Topic: Invision Power Board SQL Injection and Cross Site Scripting 0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: Invision Power Board SQL Injection and Cross Site Scripting  (Read 936 times)
AlphaWolf
AOT Administrator
Administrator
Hero Member
*****
Offline Offline

Posts: I am a geek!!



View Profile WWW
Invision Power Board SQL Injection and Cross Site Scripting
« on: May 07, 2005, 08:40:20 AM »

 FrSIRT Advisory : FrSIRT/ADV-2005-0487
CVE Reference : GENERIC-MAP-NOMATCH
Rated as : Moderate Risk
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2005-05-07

 * Technical Description *

Multiple vulnerabilities were reported in Invision Power Board, which may be exploited by attackers to execute arbitrary SQL commands or conduct Cross Site Scripting attacks. The first flaw is due to an input validation error in the "sources/login.php" file that does not properly filter specially crafted cookie ID parameters, which may be exploited to conduct SQL injection attacks. The second vulnerability is due to an input validation error in the "topics.php" script when handling a specially crafted "highlite" variable, which may be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser.

 * Affected Products *

Invision Power Board version 2.0.3 and prior

 * Solution *

Invision Power Board version 2.0.4 :
http://www.invisionpower.com/

 * References *

http://www.frsirt.com/english/advisories/2005/0487
http://www.gulftech.org/?node=research&article_id=00073-05052005
Logged

AlphaOne Tech Webmaster Resources
http://www.alphaone-tech.com/resources/
Pages: [1] Go Up Print 
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Security Announcements  |  Invisionboard  |  Topic: Invision Power Board SQL Injection and Cross Site Scripting « previous next »
Jump to:  

Powered by MySQL Powered by PHP AlphaOne Technology Support Forums | Powered by SMF 1.0.7.
© 2001-2005, Lewis Media. All Rights Reserved.
Valid XHTML 1.0! Valid CSS!