MEDIUM · 6.4

CVE-2005-0259

phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, the...

Vulnerability Description

phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the "Upload Avatar from a URL:" field to reference the target file.

CVSS Score

6.4

MEDIUM

AV:N/AC:L/Au:N/C:P/I:P/A:N
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
Phpbb GroupPhpbb2.0.0

References

FAQ

What is CVE-2005-0259?

CVE-2005-0259 is a vulnerability with a CVSS score of 6.4 (MEDIUM). phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, the...

How severe is CVE-2005-0259?

CVE-2005-0259 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-0259?

Check the references section above for vendor advisories and patch information. Affected products include: Phpbb Group Phpbb.