Lucene search

K
cveMitreCVE-2004-0359
HistoryNov 23, 2004 - 5:00 a.m.

CVE-2004-0359

2004-11-2305:00:00
mitre
web.nvd.nist.gov
114
cve-2004-0359
xss
remote execution
invision power board
security vulnerability

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.6

Confidence

High

EPSS

0.368

Percentile

97.2%

Cross-site scripting (XSS) vulnerability in index.php for Invision Power Board 1.3 final allows remote attackers to execute arbitrary script as other users via the (1) c, (2) f, (3) showtopic, (4) showuser, or (5) username parameters.

Affected configurations

Nvd
Node
invision_power_servicesinvision_boardMatch1.3.1_final
OR
invision_power_servicesinvision_boardMatch1.3_final
VendorProductVersionCPE
invision_power_servicesinvision_board1.3.1_finalcpe:2.3:a:invision_power_services:invision_board:1.3.1_final:*:*:*:*:*:*:*
invision_power_servicesinvision_board1.3_finalcpe:2.3:a:invision_power_services:invision_board:1.3_final:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.6

Confidence

High

EPSS

0.368

Percentile

97.2%

Related for CVE-2004-0359