Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2005-3764

Опубликовано: 22 нояб. 2005
Источник: nvd
CVSS2: 10
EPSS Низкий

Описание

The image gallery (imagegallery) component in Exponent CMS 0.96.3 and later versions does not properly check the MIME type of uploaded files, with unknown impact from the preview icon, possibly involving injection of HTML.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:exponent:exponent:0.94:*:*:*:*:*:*:*
cpe:2.3:a:exponent:exponent:0.95:*:*:*:*:*:*:*
cpe:2.3:a:exponent:exponent:0.96.1:*:*:*:*:*:*:*
cpe:2.3:a:exponent:exponent:0.96.3:*:*:*:*:*:*:*
cpe:2.3:a:exponent:exponent:0.96.4:*:*:*:*:*:*:*

EPSS

Процентиль: 60%
0.00402
Низкий

10 Critical

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

The image gallery (imagegallery) component in Exponent CMS 0.96.3 and later versions does not properly check the MIME type of uploaded files, with unknown impact from the preview icon, possibly involving injection of HTML.

EPSS

Процентиль: 60%
0.00402
Низкий

10 Critical

CVSS2

Дефекты

NVD-CWE-Other