CVE-2005-3310: XSS
Interpretation conflict in phpBB 2.0.17, with remote avatars and avatar uploading enabled, allows remote authenticated users to inject arbitrary web script or HTML via an HTML file with a GIF or JPEG file extension, which causes the HTML to be executed by a victim who views the file in Internet Explorer, which renders malformed image types as HTML, enabling cross-site scripting (XSS) attacks. NOTE: it could be argued that this vulnerability is due to a design flaw in Internet Explorer (CVE-2005-3312) and the proper fix should be in that browser; if so, then this should not be treated as a vulnerability in phpBB.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3310?
CVE-2005-3310 is classified as a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2005-3310?
To fix CVE-2005-3310, upgrade to phpBB version 2.0.18 or later where the vulnerability is resolved.
Who is affected by CVE-2005-3310?
CVE-2005-3310 affects phpBB version 2.0.17 when remote avatars and avatar uploading are enabled.
What kind of attack can occur due to CVE-2005-3310?
CVE-2005-3310 allows remote authenticated users to inject malicious web scripts or HTML through specially crafted image files.
What are the potential consequences of exploiting CVE-2005-3310?
Exploiting CVE-2005-3310 can lead to unauthorized actions on behalf of users in the phpBB forum, including data theft or manipulation.