Jump to content

IP.Board Calendar Application Script Insertion Vulnerability


InvisionNutCase

Recommended Posts

Posted

Secunia Advisory SA40132

IP.Board Calendar Application Script Insertion Vulnerability

Secunia Advisory SA40132
Get alerted and manage the vulnerability life cycle Free Trial
Release Date 2010-06-16 Popularity 389 views Comments 0 comments
Criticality level Less criticalcritlow_2.gifImpact Cross Site Scripting
Where From remote Authentication level Available in Customer Area
Report reliability Available in Customer Area Solution Status Unpatched Systems affected Available in Customer Area Approve distribution Available in Customer Area Software: comment_small_off.png IP.Board (Invision Power Board) 3.x
Secunia CVSS Score Available in Customer Area CVE Reference(s) No CVE references.

Posted

http://archives.neohapsis.com/archives/bugtraq/2010-06/0113.html

Vendor-Status: informed



Looks like they are aware and working on it? I might be wrong though.
Posted

I haven't noticed any attempts for script insertion with the calendar. I get anywhere from 3-10 attempts per day with the shoutbox, though. mod_security FTW. :)

Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...