📦

invision_power_board

Vendor: invision_power_services

Actively Exploited 0 CISA KEV List
PoC / Exploits 20 Code Available
Total RCEs 4 Remote Access
Total CVEs 308 Total Indexed
Avg. EPSS 2.51% Exploit Prob.
Latest CVE CVE-2021-39250 Aug 17

Security Vulnerability Index

Page 7 / 31
4.3 CVSS

Cross-site scripting (XSS) vulnerability in index.php in Invision Power Board 2.0.0 allows remote attackers to execute arbitrary web script or HTML via the Referer field in the HTTP header.

EPSS: 1.13%
4.3 CVSS

Cross-site scripting (XSS) vulnerability in Invision Power Board 1.3 Final allows remote attackers to execute arbitrary script as other users via the pop parameter in a chat action to index.php.

EPSS: 0.95%
6.8 CVSS
CVE-2003-1385
RCE Exploit Found

ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root_path parameter to reference a URL on a remote web server that contains the code.

EPSS: 4.00%