CVE-2005-0259: Medium severity Phpbb Group Phpbb vulnerability
phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the "Upload Avatar from a URL:" field to reference the target file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0259?
CVE-2005-0259 is rated as a medium-level severity vulnerability that can allow local users to read arbitrary files.
How do I fix CVE-2005-0259?
To fix CVE-2005-0259, disable the remote avatars and avatar uploading features in phpBB or upgrade to a patched version of the software.
Who is affected by CVE-2005-0259?
CVE-2005-0259 affects phpBB versions 2.0.1 through 2.0.11, and potentially earlier versions as well.
What type of vulnerability is CVE-2005-0259?
CVE-2005-0259 is a local file inclusion vulnerability that can be exploited by local users.
What causes the vulnerability in CVE-2005-0259?
The vulnerability in CVE-2005-0259 is caused by improper handling of user-supplied avatar URLs, allowing local files to be read.