Title: Invision Power Board sources/action_public/xmlout.php Arbitrary Profile Manipulation
Info
Disclosure
Jun 11, 2007
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Unknown
Description
Power Board contains a flaw that may allow a malicious user to gain unauthorized write access to another user's profile. The issue is triggered because input to the 'sources/action_public/xmlout.php' script is not validated properly. This flaw may lead to a loss of integrity.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Patch / RCS
Exploit:
Exploit Rumored
Disclosure:
OSVDB Verified,
Vendor Verified
OSVDB:
Web Related
Solution
Currently, there are no known workarounds or upgrades to correct this issue. However, the vendor has released a patch to replace the affected 'sources/action_public/xmlout.php' file, in order to address this vulnerability.