PT-2005-4273 · Microsoft+1 · Internet Explorer+1

K-Gen

·

Publicado

2005-11-03

·

Atualizado

2008-09-05

·

CVE-2005-3477

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Invision Gallery version 2.0.3
Description The issue arises from a multiple interpretation error in the image upload handling code, allowing remote attackers to conduct cross-site scripting (XSS) attacks. This occurs when an image with a mismatch between its type and extension is uploaded, and then rendered by Internet Explorer, potentially due to its handling of such files.
Recommendations For Invision Gallery version 2.0.3, consider validating image types to ensure they match their extensions before upload to prevent potential cross-site scripting attacks. As a temporary workaround, restrict the upload of images with mismatched types and extensions until a proper fix is implemented.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-3477

Produtos afetados

Internet Explorer
Invision Gallery