CVE-2005-3477: XSS

Published Nov 3, 2005
·
Updated

Multiple interpretation error in the image upload handling code in Invision Gallery 2.0.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML or script in an image whose type does not match its extension, which is rendered by Internet Explorer due to CVE-2005-3312. NOTE: it could be argued that this vulnerability is due to a design flaw in Internet Explorer and the proper fix should be in that browser; if so, then this should not be treated as a vulnerability in Invision Gallery.

Affected Software

1 affected component
Invision Power Services Invision Gallery=2.0.3

Event History

Nov 3, 2005
CVE Published
02:02 AM
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2005-3477?

CVE-2005-3477 is considered a moderate severity vulnerability due to its potential for cross-site scripting (XSS) attacks.

2

How do I fix CVE-2005-3477?

To mitigate CVE-2005-3477, update Invision Gallery to the latest version that addresses this vulnerability.

3

What type of attack is possible with CVE-2005-3477?

CVE-2005-3477 allows remote attackers to conduct cross-site scripting (XSS) attacks.

4

Which version of Invision Gallery is affected by CVE-2005-3477?

CVE-2005-3477 specifically affects Invision Gallery version 2.0.3.

5

What is the cause of the vulnerability in CVE-2005-3477?

The vulnerability in CVE-2005-3477 arises from errors in image upload handling that allow mismatched file types to execute scripts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203