CVE-2006-2059 | Invision Power Services IP.Board up to 2.1.x search.php preg_replace lastdate cross site scripting (EDB-1720 / Nessus ID 21307)
A vulnerability classified as problematic has been found in Invision Power Services IP.Board up to 2.1.x. Affected by this vulnerability is the function preg_replace of the file search.php. Performing manipulation of the argument lastdate results in basic cross site scripting.
This vulnerability is identified as CVE-2006-2059. The attack can be initiated remotely. Additionally, an exploit exists.
It is recommended to upgrade the affected component.