CVE-2005-2817
Last modified
CVE-2005-2817 is a vulnerability of currently unknown severity. Simple Machines Forum (SMF) 1-0-5 and earlier supports the use of URLs for avatar images, which allows remote attackers to monitor sensitive information of forum visitors such as IP address and user agent, as demonstrated using a PHP script on a malicious server.. EPSS estimates a 1.55% chance of exploitation in the next 30 days.
Description
Simple Machines Forum (SMF) 1-0-5 and earlier supports the use of URLs for avatar images, which allows remote attackers to monitor sensitive information of forum visitors such as IP address and user agent, as demonstrated using a PHP script on a malicious server.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Simple Machines | Simple Machines Forum | 1.0.5 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-2817?
How severe is CVE-2005-2817?
How do I fix CVE-2005-2817?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-2811Untrusted search path vulnerability in Net-SNMP 5.2.1.2 and …
- CVE-2005-2812man2web allows remote attackers to execute arbitrary command…
- CVE-2005-2813Directory traversal vulnerability in FlatNuke 2.5.6 and poss…
- CVE-2005-2814Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.6 a…
- CVE-2005-2815print.php in FlatNuke 2.5.6 allows remote attackers to obtai…
- CVE-2005-2816Cross-site scripting (XSS) vulnerability in Greymatter allow…
- CVE-2005-2818Cross-site scripting (XSS) vulnerability in DownFile 1.3 all…
- CVE-2005-2819DownFile 1.3 allows remote attackers to gain administrator p…
- CVE-2005-2820Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 …
- CVE-2005-2827The thread termination routine in the kernel for Windows NT …
- CVE-2005-2829Multiple design errors in Microsoft Internet Explorer 5.01, …
- CVE-2005-2830Microsoft Internet Explorer 5.01, 5.5, and 6, when using an …
Are you affected by CVE-2005-2817?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
