Cross-site scripting (XSS) vulnerability in index.php in Invision Power Board 2.0.0 allows remote attackers to execute arbitrary web script or HTML via the Referer field in the HTTP header.
📦
invision_power_board
Vendor: invision_power_services
Actively Exploited
0
CISA KEV List
PoC / Exploits
20
Code Available
Total RCEs
4
Remote Access
Total CVEs
308
Total Indexed
Avg. EPSS
2.51%
Exploit Prob.
Security Vulnerability Index
Page 7 / 31
4.3
CVSS
Severity: MEDIUM
4.3
CVSS
Cross-site scripting (XSS) vulnerability in Invision Power Board 1.3 Final allows remote attackers to execute arbitrary script as other users via the pop parameter in a chat action to index.php.
Severity: MEDIUM
6.8
CVSS
CVE-2003-1385
RCE
Exploit Found
ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root_path parameter to reference a URL on a remote web server that contains the code.
Severity: MEDIUM