CVE Database
/

CVE-2005-3975

Back to search

CVE-2005-3975

Published: Dec 3, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

Interpretation conflict in file.inc in Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3 allows remote authenticated users to inject arbitrary web script or HTML via HTML in a file with a GIF or JPEG file extension, which causes the HTML to be executed by a victim who views the file in Internet Explorer as a result of CVE-2005-3312. NOTE: it could be argued that this vulnerability is due to a design flaw in Internet Explorer and the proper fix should be in that browser; if so, then this should not be treated as a vulnerability in Drupal.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2005-2684
vdb-entry
x_refsource_VUPEN
220
third-party-advisory
x_refsource_SREASON
DSA-958
vendor-advisory
x_refsource_DEBIAN
18630
third-party-advisory
x_refsource_SECUNIA
15663
vdb-entry
x_refsource_BID
17824
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now