CVE Vulnerabilities

CVE-2005-0259

Published: Mar 14, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, then modifying the Upload Avatar from a URL: field to reference the target file.

Affected Software

NameVendorStart VersionEnd Version
PhpbbPhpbb_group2.0.0 (including)2.0.0 (including)
PhpbbPhpbb_group2.0.1 (including)2.0.1 (including)
PhpbbPhpbb_group2.0.2 (including)2.0.2 (including)
PhpbbPhpbb_group2.0.3 (including)2.0.3 (including)
PhpbbPhpbb_group2.0.4 (including)2.0.4 (including)
PhpbbPhpbb_group2.0.5 (including)2.0.5 (including)
PhpbbPhpbb_group2.0.6 (including)2.0.6 (including)
PhpbbPhpbb_group2.0.6c (including)2.0.6c (including)
PhpbbPhpbb_group2.0.6d (including)2.0.6d (including)
PhpbbPhpbb_group2.0.7 (including)2.0.7 (including)
PhpbbPhpbb_group2.0.7a (including)2.0.7a (including)
PhpbbPhpbb_group2.0.8 (including)2.0.8 (including)
PhpbbPhpbb_group2.0.8a (including)2.0.8a (including)
PhpbbPhpbb_group2.0.9 (including)2.0.9 (including)
PhpbbPhpbb_group2.0.10 (including)2.0.10 (including)
PhpbbPhpbb_group2.0.11 (including)2.0.11 (including)
PhpbbPhpbb_group2.0_beta1 (including)2.0_beta1 (including)
PhpbbPhpbb_group2.0_rc1 (including)2.0_rc1 (including)
PhpbbPhpbb_group2.0_rc2 (including)2.0_rc2 (including)
PhpbbPhpbb_group2.0_rc3 (including)2.0_rc3 (including)
PhpbbPhpbb_group2.0_rc4 (including)2.0_rc4 (including)

References