← Vulnerability feed

Vulnerability record · CVE-2005-3310 · published 26 October 2005

CVE-2005-3310: Phpbb group phpbb vulnerability

Phpbb Group · Phpbb

Interpretation conflict in phpBB 2.0.17, with remote avatars and avatar uploading enabled, allows remote authenticated users to inject arbitrary web script or HTML via an HTML file with a GIF or JPEG file extension, which causes the HTML to be executed by a victim who views the file in Internet Explorer, which renders malformed image types as HTML, enabling cross-site scripting (XSS) attacks. NOTE: it could be argued that this vulnerability is due to a design flaw in Internet Explorer (CVE-2005-3312) and the proper fix should be in that browser; if so, then this should not be treated as a vulnerability in phpBB.

3.5 CVSS 2.0 Low EPSS 1.2% · top 33.9%
3.5CVSS 2.0 base score
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Interpretation conflict in phpBB 2.0.17, with remote avatars and avatar uploading enabled, allows remote authenticated users to inject arbitrary web script or HTML via an HTML file with a GIF or JPEG file extension, which causes the HTML to be executed by a victim who views the file in Internet Explorer, which renders malformed image types as HTML, enabling cross-site scripting (XSS) attacks. NOTE: it could be argued that this vulnerability is due to a design flaw in Internet Explorer (CVE-2005-3312) and the proper fix should be in that browser; if so, then this should not be treated as a vulnerability in phpBB.

AV:N/AC:M/Au:S/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-3310 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-1695Phpbb group phpbb vulnerabilityPHP remote file inclusion vulnerability in includes/usercp_register.php in phpBB 2.0.19 allows remote attackers to execute arbitrary PHP code via a U…EPSS 1.9%10.0CVE-2006-6839Phpbb group phpbb vulnerabilityUnspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to "criteria for 'bad' redirection targets."EPSS 1.6%10.0CVE-2006-6840Phpbb group phpbb vulnerabilityUnspecified vulnerability in phpBB before 2.0.22 has unknown impact and remote attack vectors related to a "negative start parameter."EPSS 1.6%10.0CVE-2006-6841Phpbb group phpbb vulnerabilityCertain forms in phpBB before 2.0.22 lack session checks, which has unknown impact and remote attack vectors.EPSS 1.6%10.0CVE-2002-1537Phpbb group phpbb vulnerabilityadmin_ug_auth.php in phpBB 2.0.0 allows local users to gain administrator privileges by directly calling admin_ug_auth.php with modifed form fields s…EPSS 2.5%10.0CVE-2002-2176Phpbb group phpbb vulnerabilitySQL injection vulnerability in Gender MOD 1.1.3 allows remote attackers to gain administrative access via the user_level parameter in the User Profil…EPSS 3.3%10.0CVE-2002-0473Phpbb group phpbb vulnerabilitydb.php in phpBB 2.0 (aka phpBB2) RC-3 and earlier allows remote attackers to execute arbitrary code from remote servers via the phpbb_root_path param…EPSS 5.3%7.5CVE-2006-5435Phpbb group phpbb vulnerabilityPHP remote file inclusion vulnerability in groupcp.php in phpBB 2.0.10 and earlier allows remote attackers to execute arbitrary PHP code via a URL in…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2005-3310), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.