CVE-2005-1115: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Photo Album 2.0.53 module for phpBB allow remote attackers to inject arbitrary web script or HTML via the bsid parameter to (1) albumcat.php or (2) albumcomment.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-1115?
CVE-2005-1115 has been identified as a serious vulnerability due to its potential for remote code execution via cross-site scripting.
How do I fix CVE-2005-1115?
To fix CVE-2005-1115, upgrade to a patched version of the phpBB Photo Album module that resolves these XSS vulnerabilities.
What are the affected versions in CVE-2005-1115?
CVE-2005-1115 affects multiple versions of phpBB, including 2.0.0 through 2.0.13 and the Smartor Photo Album version 2.0.53.
What can attackers achieve with CVE-2005-1115?
Attackers exploiting CVE-2005-1115 can inject arbitrary web scripts or HTML, potentially compromising user data.
Are there any workarounds for CVE-2005-1115?
While the best practice is to upgrade, temporary workarounds such as URL sanitization can mitigate the risks associated with CVE-2005-1115.