Unrated severityNVD Advisory· Published Jun 23, 2006· Updated Apr 16, 2026
CVE-2006-3197
CVE-2006-3197
Description
Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.1.6 and earlier allows remote attackers to inject arbitrary web script or HTML via a POST that contains hexadecimal-encoded HTML.
Affected products
14cpe:2.3:a:invision_power_services:invision_power_board:2.1:*:*:*:*:*:*:*+ 13 more
- cpe:2.3:a:invision_power_services:invision_power_board:2.1:*:*:*:*:*:*:*
- cpe:2.3:a:invision_power_services:invision_power_board:2.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:invision_power_services:invision_power_board:2.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:invision_power_services:invision_power_board:2.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:invision_power_services:invision_power_board:2.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:invision_power_services:invision_power_board:2.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:invision_power_services:invision_power_board:2.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:invision_power_services:invision_power_board:2.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:invision_power_services:invision_power_board:2.1_alpha2:*:*:*:*:*:*:*
- cpe:2.3:a:invision_power_services:invision_power_board:2.1_beta2:*:*:*:*:*:*:*
- cpe:2.3:a:invision_power_services:invision_power_board:2.1_beta3:*:*:*:*:*:*:*
- cpe:2.3:a:invision_power_services:invision_power_board:2.1_beta4:*:*:*:*:*:*:*
- cpe:2.3:a:invision_power_services:invision_power_board:2.1_beta5:*:*:*:*:*:*:*
- cpe:2.3:a:invision_power_services:invision_power_board:2.1_rc1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7News mentions
0No linked articles in our index yet.