CVE-2005-0886
Invision Power Board <= 2.0.2 - Cross-Site Scripting via HTTP POST Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2005-0886. PoCs published by Woody Hughes.
AI-analyzed exploit summary The provided text describes an HTML injection vulnerability in Invision Power Board, where insufficient sanitization allows an attacker to inject an IFRAME via HTTP POST. The example demonstrates a malicious IFRAME injection but lacks executable exploit code.
Description
Cross-site scripting (XSS) vulnerability in Invision Power Board 2.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an HTTP POST request.
Exploits (1)
The provided text describes an HTML injection vulnerability in Invision Power Board, where insufficient sanitization allows an attacker to inject an IFRAME via HTTP POST. The example demonstrates a malicious IFRAME injection but lacks executable exploit code.