CVE-2005-3975

Drupal 4.5.0-4.5.5 & 4.6.0-4.6.3 - XSS

Title source: llm
STIX 2.1

Description

Interpretation conflict in file.inc in Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3 allows remote authenticated users to inject arbitrary web script or HTML via HTML in a file with a GIF or JPEG file extension, which causes the HTML to be executed by a victim who views the file in Internet Explorer as a result of CVE-2005-3312. NOTE: it could be argued that this vulnerability is due to a design flaw in Internet Explorer and the proper fix should be in that browser; if so, then this should not be treated as a vulnerability in Drupal.

References (9)

Core 9
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/2684
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/220
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2006/dsa-958
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18630
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/15663
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/418291/100/0/threaded
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17824
Patch, Vendor Advisory x_refsource_confirm
http://drupal.org/files/sa-2005-008/advisory.txt
Various Sources x_refsource_misc
http://drupal.org/files/sa-2005-008/4.6.3.patch

Scores

EPSS 0.0082
EPSS Percentile 74.6%

Details

Status published
Products (10)
drupal/drupal 4.5.0
drupal/drupal 4.5.1
drupal/drupal 4.5.2
drupal/drupal 4.5.3
drupal/drupal 4.5.4
drupal/drupal 4.5.5
drupal/drupal 4.6.0
drupal/drupal 4.6.1
drupal/drupal 4.6.2
drupal/drupal 4.6.3
Published Dec 03, 2005
Tracked Since Feb 18, 2026