Security Advisory

CVE-2006-5204

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2006-10-09 19:00:00
Last updated 2024-08-07 19:41:05
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Cross-site scripting (XSS) vulnerability in action_admin/member.php in Invision Power Board (IPB) 2.1.7 and earlier allows remote authenticated users to inject arbitrary web script or HTML via a reference to a script in the avatar setting, which can be leveraged for a cross-site request forgery (CSRF) attack involving forced SQL execution by an admin.