
CVE-2004-1578
https://notcve.org/view.php?id=CVE-2004-1578
31 Dec 2004 — Cross-site scripting (XSS) vulnerability in index.php in Invision Power Board 2.0.0 allows remote attackers to execute arbitrary web script or HTML via the Referer field in the HTTP header. • http://marc.info/?l=bugtraq&m=109701091207517&w=2 •

CVE-2004-2279
https://notcve.org/view.php?id=CVE-2004-2279
31 Dec 2004 — Cross-site scripting (XSS) vulnerability in Invision Power Board 1.3 Final allows remote attackers to execute arbitrary script as other users via the pop parameter in a chat action to index.php. • http://archives.neohapsis.com/archives/bugtraq/2004-03/0082.html •

CVE-2003-1385 – Invision Board 1.1.1 - 'ipchat.php' Remote File Inclusion
https://notcve.org/view.php?id=CVE-2003-1385
31 Dec 2003 — ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root_path parameter to reference a URL on a remote web server that contains the code. • https://www.exploit-db.com/exploits/22295 • CWE-94: Improper Control of Generation of Code ('Code Injection') •