CVE-2005-0477

Invision Power Services Invision Power Board - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in the SML code for Invision Power Board 1.3.1 FINAL allows remote attackers to inject arbitrary web script via (1) a signature file or (2) a message post containing an IMG tag within a COLOR tag whose style is set to background:url.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Daniel A. · textwebappsphp
https://www.exploit-db.com/exploits/25143

Scores

EPSS 0.0055
EPSS Percentile 67.6%

Classification

CWE
CWE-79
Status draft

Affected Products (8)

invision_power_services/invision_power_board
invision_power_services/invision_power_board
invision_power_services/invision_power_board
invision_power_services/invision_power_board
invision_power_services/invision_power_board
invision_power_services/invision_power_board
invision_power_services/invision_power_board
invision_power_services/invision_power_board

Timeline

Published Mar 30, 2005
Tracked Since Feb 18, 2026