PT-2005-5516 · Ez Systems · Ez Publish

Publicado

2005-12-31

·

Atualizado

2018-09-27

·

CVE-2005-4855

CVSS v2.0

3.5

Baixa

VetorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: eZ publish versions 3.5 through 3.5.5 eZ publish versions 3.6 through 3.6.2 eZ publish versions 3.7 through 3.7.0rc2 eZ publish versions 3.8 through 20050922
Description: The issue allows remote authenticated users to upload certain types of files, such as .js files, due to a lack of restriction on Image datatype uploads to image content types. This may enable cross-site scripting (XSS) attacks or other attacks.
Recommendations: For eZ publish versions 3.5 through 3.5.5, update to version 3.5.5 or later. For eZ publish versions 3.6 through 3.6.2, update to version 3.6.2 or later. For eZ publish versions 3.7 through 3.7.0rc2, update to version 3.7.0rc2 or later. For eZ publish versions 3.8 through 20050922, update to a version later than 20050922.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2005-4855

Produtos afetados

Ez Publish