CVE-2007-4912
Invision Power Services Invision Power Board - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in ips_kernel/class_ajax.php in Invision Power Board (IPB or IP.Board) 2.3.1 up to 20070912 allows remote attackers to inject arbitrary web script or HTML into user profile fields via unspecified vectors related to character sets other than iso-8859-1 or utf-8.
References (5)
Scores
EPSS
0.0030
EPSS Percentile
53.2%
Classification
CWE
CWE-79
Status
draft
Affected Products (6)
invision_power_services/invision_power_board
invision_power_services/invision_power_board
invision_power_services/invision_power_board
invision_power_services/invision_power_board
invision_power_services/invision_power_board
invision_power_services/invision_power_board
Timeline
Published
Sep 17, 2007
Tracked Since
Feb 18, 2026