Multiple cross-site scripting (XSS) vulnerabilities in index.php for Invision Power Board (IPB) 2.0.3 and 2.1 Alpha 2 allows remote attackers to inject arbitrary web script or HTML via the (1) act, (2) Members, (3) calendar, or (4) HID parameters.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Invision_power_board | Invision_power_services | 2.0.3 (including) | 2.0.3 (including) |
Invision_power_board | Invision_power_services | 2.1_alpha2 (including) | 2.1_alpha2 (including) |