CVE Vulnerabilities

CVE-2007-2349

Published: Apr 30, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Cross-site scripting (XSS) vulnerability in Invision Power Board (IP.Board) 2.1.x and 2.2.x allows remote attackers to inject arbitrary web script or HTML by uploading crafted images or PDF files.

Affected Software

NameVendorStart VersionEnd Version
Invision_power_boardInvision_power_services2.1 (including)2.1 (including)
Invision_power_boardInvision_power_services2.2 (including)2.2 (including)

References