CVE Database
/

CVE-2005-3310

Back to search

CVE-2005-3310

Published: Oct 25, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

Interpretation conflict in phpBB 2.0.17, with remote avatars and avatar uploading enabled, allows remote authenticated users to inject arbitrary web script or HTML via an HTML file with a GIF or JPEG file extension, which causes the HTML to be executed by a victim who views the file in Internet Explorer, which renders malformed image types as HTML, enabling cross-site scripting (XSS) attacks. NOTE: it could be argued that this vulnerability is due to a design flaw in Internet Explorer (CVE-2005-3312) and the proper fix should be in that browser; if so, then this should not be treated as a vulnerability in phpBB.

VendorProductVersions

n/a

n/a

affected
n/a

References

15170
vdb-entry
x_refsource_BID
DSA-925
vendor-advisory
x_refsource_DEBIAN
18098
third-party-advisory
x_refsource_SECUNIA
17295
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now