Vulnerability Description
Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt attachment.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Invisioncommunity | Invision Power Board | >= 2.0, <= 3.0.4 |
| Microsoft | Internet Explorer | 5 |
Related Weaknesses (CWE)
References
- http://community.invisionpower.com/topic/300051-invision-power-board-305-releaseBroken LinkVendor Advisory
- https://packetstormsecurity.com/files/83624/Invision-Power-Board-3.0.4-Cross-SitExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/33394ExploitThird Party AdvisoryVDB Entry
- https://www.securityfocus.com/bid/37263/infoThird Party AdvisoryVDB Entry
- http://community.invisionpower.com/topic/300051-invision-power-board-305-releaseBroken LinkVendor Advisory
- https://packetstormsecurity.com/files/83624/Invision-Power-Board-3.0.4-Cross-SitExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/33394ExploitThird Party AdvisoryVDB Entry
- https://www.securityfocus.com/bid/37263/infoThird Party AdvisoryVDB Entry
FAQ
What is CVE-2009-5159?
CVE-2009-5159 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt attachment.
How severe is CVE-2009-5159?
CVE-2009-5159 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-5159?
Check the references section above for vendor advisories and patch information. Affected products include: Invisioncommunity Invision Power Board, Microsoft Internet Explorer.