CVE Database
/

CVE-2006-1326

Back to search

CVE-2006-1326

Published: Mar 21, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in Invision Power Board 2.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) result_type, (2) search_in, (3) nav, (4) forums, and (5) s parameters in the Search action to index.php; (6) st parameter to index.php with showtopics set to 1; (7) m, (8) y, and (9) d parameters in a calendar action; (10) t parameter in a Print action; (11) MID parameter in a Mail action; (12) HID parameter in a Help action; (13) active parameter in a search action; (14) sort_order, (15) max_results, or (16) sort_key parameter in a Members action.

VendorProductVersions

n/a

n/a

affected
n/a

References

25010
vdb-entry
x_refsource_OSVDB
25013
vdb-entry
x_refsource_OSVDB
25011
vdb-entry
x_refsource_OSVDB
25014
vdb-entry
x_refsource_OSVDB
20060317 XSS IN Invision Power Board
mailing-list
x_refsource_BUGTRAQ
25012
vdb-entry
x_refsource_OSVDB
17144
vdb-entry
x_refsource_BID
25009
vdb-entry
x_refsource_OSVDB
25015
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now