SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2005-0259

phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the "Upload Avatar from a URL:" field to…

MEDIUM 6.4EPSS 2.04%

Does this matter?

Lower severity and a low EPSS score (2.04%). Track it; it rarely justifies an emergency change on its own.

Description

phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the "Upload Avatar from a URL:" field to reference the target file.

CVSS 2.0
6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS
2.04% probability · 80th percentile
CISA KEV
Not listed
Affected
phpbb group/phpbb
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.