CVE-2005-3477
Last modified
CVE-2005-3477 is a vulnerability of currently unknown severity. Multiple interpretation error in the image upload handling code in Invision Gallery 2.0.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML or script in an image whose type does not match its extension, which is rendered by Internet Explorer due to CVE-2005-3312. NOTE: it could be argued that this vulnerability is due to a design flaw in Internet Explorer and the proper fix should be in that browser; if so, then this should not be treated as a vulnerability in Invision Gallery.. EPSS estimates a 1.16% chance of exploitation in the next 30 days.
Description
Multiple interpretation error in the image upload handling code in Invision Gallery 2.0.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML or script in an image whose type does not match its extension, which is rendered by Internet Explorer due to CVE-2005-3312. NOTE: it could be argued that this vulnerability is due to a design flaw in Internet Explorer and the proper fix should be in that browser; if so, then this should not be treated as a vulnerability in Invision Gallery.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Invision Power Services | Invision Gallery | 2.0.3 |
References
- http://secunia.com/advisories/17393Vendor Advisory
- http://secunia.com/advisories/17393Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-3477?
How severe is CVE-2005-3477?
How do I fix CVE-2005-3477?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-3471Directory traversal vulnerability in the ruleset view for Ma…
- CVE-2005-3472Unspecified vulnerability in Sun Java System Communications …
- CVE-2005-3473Multiple cross-site scripting (XSS) vulnerabilities in Simpl…
- CVE-2005-3474The aries.sys driver in Sony First4Internet XCP DRM software…
- CVE-2005-3475Hasbani Web Server (WindWeb) 2.0 allows remote attackers to …
- CVE-2005-3476Unspecified vulnerability in HP OpenVMS Integrity 8.2-1 and …
- CVE-2005-3478SQL injection vulnerability in index.php in PHPCafe.net Tuto…
- CVE-2005-3479Cross-site scripting (XSS) vulnerability in login.asp in Rin…
- CVE-2005-3480login.asp in Ringtail CaseBook 6.1.0 displays different erro…
- CVE-2005-3481Cisco IOS 12.0 to 12.4 might allow remote attackers to execu…
- CVE-2005-3482Cisco 1200, 1131, and 1240 series Access Points, when operat…
- CVE-2005-3483Buffer overflow in GO-Global for Windows 3.1.0.3270 and earl…
Are you affected by CVE-2005-3477?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
