CVE-2005-3975
Debian Linux Security Advisory 958-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Interpretation conflict in file.inc in Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3 allows remote authenticated users to inject arbitrary web script or HTML via HTML in a file with a GIF or JPEG file extension, which causes the HTML to be executed by a victim who views the file in Internet Explorer as a result of CVE-2005-3312. NOTE: it could be argued that this vulnerability is due to a design flaw in Internet Explorer and the proper fix should be in that browser; if so, then this should not be treated as a vulnerability in Drupal.
Several security related problems have been discovered in Drupal. Several cross-site scripting vulnerabilities allow remote attackers to inject arbitrary web script or HTML. When running on PHP5, Drupal does not correctly enforce user privileges, which allows remote attackers to bypass the 'access user profiles' permission. An interpretation conflict allows remote authenticated users to inject arbitrary web script or HTML via HTML in a file with a GIF or JPEG file extension.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2005-12-03 CVE Reserved
- 2005-12-03 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://drupal.org/files/sa-2005-008/4.6.3.patch | X_refsource_misc | |
http://secunia.com/advisories/18630 | Third Party Advisory | |
http://securityreason.com/securityalert/220 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/418291/100/0/threaded | Mailing List | |
http://www.vupen.com/english/advisories/2005/2684 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://drupal.org/files/sa-2005-008/advisory.txt | 2018-10-19 | |
http://secunia.com/advisories/17824 | 2018-10-19 | |
http://www.securityfocus.com/bid/15663 | 2018-10-19 |
URL | Date | SRC |
---|---|---|
http://www.debian.org/security/2006/dsa-958 | 2018-10-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 4.5.0 Search vendor "Drupal" for product "Drupal" and version "4.5.0" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 4.5.1 Search vendor "Drupal" for product "Drupal" and version "4.5.1" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 4.5.2 Search vendor "Drupal" for product "Drupal" and version "4.5.2" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 4.5.3 Search vendor "Drupal" for product "Drupal" and version "4.5.3" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 4.5.4 Search vendor "Drupal" for product "Drupal" and version "4.5.4" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 4.5.5 Search vendor "Drupal" for product "Drupal" and version "4.5.5" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 4.6.0 Search vendor "Drupal" for product "Drupal" and version "4.6.0" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 4.6.1 Search vendor "Drupal" for product "Drupal" and version "4.6.1" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 4.6.2 Search vendor "Drupal" for product "Drupal" and version "4.6.2" | - |
Affected
| ||||||
Drupal Search vendor "Drupal" | Drupal Search vendor "Drupal" for product "Drupal" | 4.6.3 Search vendor "Drupal" for product "Drupal" and version "4.6.3" | - |
Affected
|