PT-2005-5516 · Ez Systems · Ez Publish

Published

2005-12-31

·

Updated

2018-09-27

·

CVE-2005-4855

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: eZ publish versions 3.5 through 3.5.5 eZ publish versions 3.6 through 3.6.2 eZ publish versions 3.7 through 3.7.0rc2 eZ publish versions 3.8 through 20050922
Description: The issue allows remote authenticated users to upload certain types of files, such as .js files, due to a lack of restriction on Image datatype uploads to image content types. This may enable cross-site scripting (XSS) attacks or other attacks.
Recommendations: For eZ publish versions 3.5 through 3.5.5, update to version 3.5.5 or later. For eZ publish versions 3.6 through 3.6.2, update to version 3.6.2 or later. For eZ publish versions 3.7 through 3.7.0rc2, update to version 3.7.0rc2 or later. For eZ publish versions 3.8 through 20050922, update to a version later than 20050922.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2005-4855

Affected Products

Ez Publish