Vulnerability Details CVE-2006-5204
Cross-site scripting (XSS) vulnerability in action_admin/member.php in Invision Power Board (IPB) 2.1.7 and earlier allows remote authenticated users to inject arbitrary web script or HTML via a reference to a script in the avatar setting, which can be leveraged for a cross-site request forgery (CSRF) attack involving forced SQL execution by an admin.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 64.5%
CVSS Severity
CVSS v2 Score 2.1
Products affected by CVE-2006-5204
-
cpe:2.3:a:invision_power_services:invision_power_board:*
-
cpe:2.3:a:invision_power_services:invision_power_board:1.0
-
cpe:2.3:a:invision_power_services:invision_power_board:1.0.1
-
cpe:2.3:a:invision_power_services:invision_power_board:1.0.3
-
cpe:2.3:a:invision_power_services:invision_power_board:1.1.1
-
cpe:2.3:a:invision_power_services:invision_power_board:1.1.2
-
cpe:2.3:a:invision_power_services:invision_power_board:1.2
-
cpe:2.3:a:invision_power_services:invision_power_board:1.3
-
cpe:2.3:a:invision_power_services:invision_power_board:1.3.1_final
-
cpe:2.3:a:invision_power_services:invision_power_board:1.3_final
-
cpe:2.3:a:invision_power_services:invision_power_board:2.0
-
cpe:2.3:a:invision_power_services:invision_power_board:2.0.0
-
cpe:2.3:a:invision_power_services:invision_power_board:2.0.1
-
cpe:2.3:a:invision_power_services:invision_power_board:2.0.2
-
cpe:2.3:a:invision_power_services:invision_power_board:2.0.3
-
cpe:2.3:a:invision_power_services:invision_power_board:2.0.4
-
cpe:2.3:a:invision_power_services:invision_power_board:2.0.x
-
cpe:2.3:a:invision_power_services:invision_power_board:2.0_alpha3
-
cpe:2.3:a:invision_power_services:invision_power_board:2.0_pdr3
-
cpe:2.3:a:invision_power_services:invision_power_board:2.0_pf1
-
cpe:2.3:a:invision_power_services:invision_power_board:2.0_pf2
-
cpe:2.3:a:invision_power_services:invision_power_board:2.1
-
cpe:2.3:a:invision_power_services:invision_power_board:2.1.0
-
cpe:2.3:a:invision_power_services:invision_power_board:2.1.1
-
cpe:2.3:a:invision_power_services:invision_power_board:2.1.2
-
cpe:2.3:a:invision_power_services:invision_power_board:2.1.3
-
cpe:2.3:a:invision_power_services:invision_power_board:2.1.4
-
cpe:2.3:a:invision_power_services:invision_power_board:2.1.5
-
cpe:2.3:a:invision_power_services:invision_power_board:2.1.5_2006-03-08
-
cpe:2.3:a:invision_power_services:invision_power_board:2.1.6
-
cpe:2.3:a:invision_power_services:invision_power_board:2.1_alpha2
-
cpe:2.3:a:invision_power_services:invision_power_board:2.1_beta2
-
cpe:2.3:a:invision_power_services:invision_power_board:2.1_beta3
-
cpe:2.3:a:invision_power_services:invision_power_board:2.1_beta4
-
cpe:2.3:a:invision_power_services:invision_power_board:2.1_beta5
-
cpe:2.3:a:invision_power_services:invision_power_board:2.1_rc1