Unrated severityNVD Advisory· Published May 31, 2007· Updated Apr 23, 2026
CVE-2007-2963
CVE-2007-2963
Description
Multiple cross-site scripting (XSS) vulnerabilities in Invision Power Board (IPB or IP.Board) 2.2.2, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via (1) module_bbcodeloader.php, (2) module_div.php, (3) module_email.php, (4) module_image.php, (5) module_link.php, or (6) the editorid parameter to module_table.php in jscripts/folder_rte_files/. NOTE: some details were obtained from third party sources.
Affected products
1- cpe:2.3:a:invision_power_services:invision_power_board:*:*:*:*:*:*:*:*Range: <=2.2.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- forums.invisionpower.com/index.phpnvdPatch
- secunia.com/advisories/25437nvdPatchVendor Advisory
- www.securityfocus.com/bid/24244nvdPatch
- osvdb.org/35430nvd
- osvdb.org/35431nvd
- osvdb.org/35432nvd
- osvdb.org/35433nvd
- osvdb.org/35434nvd
- osvdb.org/35435nvd
- www.vupen.com/english/advisories/2007/1993nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/34616nvd
News mentions
0No linked articles in our index yet.