CVE-2005-0259
phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the "Upload Avatar from a URL:" field to…
Does this matter?
Lower severity and a low EPSS score (2.04%). Track it; it rarely justifies an emergency change on its own.
Description
phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the "Upload Avatar from a URL:" field to reference the target file.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 2.04% probability · 80th percentile
- CISA KEV
- Not listed
- Affected
- phpbb group/phpbb
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/14362/
- http://www.gentoo.org/security/en/glsa/glsa-200503-02.xml
- http://www.idefense.com/application/poi/display?id=204&type=vulnerabilitiesPatch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/774686US Government Resource
- http://www.phpbb.com/support/documents.php?mode=changelogVendor Advisory
- http://secunia.com/advisories/14362/
- http://www.gentoo.org/security/en/glsa/glsa-200503-02.xml
- http://www.idefense.com/application/poi/display?id=204&type=vulnerabilitiesPatch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/774686US Government Resource
- http://www.phpbb.com/support/documents.php?mode=changelogVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.