CVE-2007-4912

Invision Power Services Invision Power Board - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in ips_kernel/class_ajax.php in Invision Power Board (IPB or IP.Board) 2.3.1 up to 20070912 allows remote attackers to inject arbitrary web script or HTML into user profile fields via unspecified vectors related to character sets other than iso-8859-1 or utf-8.

Scores

EPSS 0.0030
EPSS Percentile 53.2%

Classification

CWE
CWE-79
Status draft

Affected Products (6)

invision_power_services/invision_power_board
invision_power_services/invision_power_board
invision_power_services/invision_power_board
invision_power_services/invision_power_board
invision_power_services/invision_power_board
invision_power_services/invision_power_board

Timeline

Published Sep 17, 2007
Tracked Since Feb 18, 2026