OSVDB ID: 35436

Title: Invision Power Board sources/action_public/xmlout.php Arbitrary Profile Manipulation

Info

Disclosure

Jun 11, 2007

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

Power Board contains a flaw that may allow a malicious user to gain unauthorized write access to another user's profile. The issue is triggered because input to the 'sources/action_public/xmlout.php' script is not validated properly. This flaw may lead to a loss of integrity.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Patch / RCS
Exploit: Exploit Rumored
Disclosure: OSVDB Verified, Vendor Verified
OSVDB: Web Related

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, the vendor has released a patch to replace the affected 'sources/action_public/xmlout.php' file, in order to address this vulnerability.

Products

Invision Power Services, Inc

Invision Power Board

2.2.0
2.2.2

References

Credit

  • iMMENSE -


Direct URL: http://osvdb.org/35436