Page 10 of 61 results (0.006 seconds)

CVSS: 4.3EPSS: 1%CPEs: 1EXPL: 8

Multiple cross-site scripting (XSS) vulnerabilities in Invision Power Board 2.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) result_type, (2) search_in, (3) nav, (4) forums, and (5) s parameters in the Search action to index.php; (6) st parameter to index.php with showtopics set to 1; (7) m, (8) y, and (9) d parameters in a calendar action; (10) t parameter in a Print action; (11) MID parameter in a Mail action; (12) HID parameter in a Help action; (13) active parameter in a search action; (14) sort_order, (15) max_results, or (16) sort_key parameter in a Members action. • https://www.exploit-db.com/exploits/27437 https://www.exploit-db.com/exploits/27438 https://www.exploit-db.com/exploits/27441 https://www.exploit-db.com/exploits/27440 https://www.exploit-db.com/exploits/27439 https://www.exploit-db.com/exploits/27436 https://www.exploit-db.com/exploits/27442 http://www.osvdb.org/25009 http://www.osvdb.org/25010 http://www.osvdb.org/25011 http://www.osvdb.org/25012 http://www.osvdb.org/25013 http://www.osvdb&# •

CVSS: 5.8EPSS: 0%CPEs: 2EXPL: 0

Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.0.4 and 2.1.4 before 20060130 allows remote attackers to steal cookies and probably conduct other activities when the victim is using Internet Explorer. • http://forums.invisionpower.com/index.php?showtopic=206790 http://secunia.com/advisories/19141 http://www.vupen.com/english/advisories/2006/0861 •

CVSS: 7.5EPSS: 4%CPEs: 2EXPL: 0

Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 2.0.4 and 2.1.4 before 20060105 allow remote attackers to execute arbitrary SQL commands via cookies, related to (1) arrays of id/stamp pairs and (2) the keys in arrays of key/value pairs in ipsclass.php; (3) the topics variable in usercp.php; and the topicsread cookie in (4) topics.php, (5) search.php, and (6) forums.php. • http://forums.invisionpower.com/index.php?act=Attach&type=post&id=9642 http://forums.invisionpower.com/index.php?showtopic=204627 http://secunia.com/advisories/19141 http://www.vupen.com/english/advisories/2006/0861 https://exchange.xforce.ibmcloud.com/vulnerabilities/25100 •

CVSS: 5.1EPSS: 0%CPEs: 1EXPL: 1

Invision Power Board 2.1.4 allows remote attackers to hijack sessions and possibly gain administrative privileges by obtaining the session ID from the s parameter, then replaying it in another request. • http://www.securityfocus.com/archive/1/427751/100/0/threaded http://www.securityfocus.com/archive/1/427847/100/0/threaded •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 2

SQL injection vulnerability in index.php, possibly during a showtopic operation, in Invision Power Board (IPB) 2.1.5 allows remote attackers to execute arbitrary SQL commands via the st parameter. • https://www.exploit-db.com/exploits/27361 http://www.securityfocus.com/archive/1/426875/100/0/threaded http://www.securityfocus.com/archive/1/430357/100/0/threaded http://www.securityfocus.com/bid/16971 https://exchange.xforce.ibmcloud.com/vulnerabilities/25254 •