Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2005-4856

Опубликовано: 31 дек. 2005
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

The admin interface in eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051110 does not properly handle authorization errors, which allows remote attackers to obtain sensitive information and see the admin pagelayout and associated templates via a request with (1) "anything after the url" or (2) a "wrong url".

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ez:ez_publish:*:*:*:*:*:*:*:*
Версия до 3.8.0 (включая)
cpe:2.3:a:ez:ez_publish:3.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ez:ez_publish:3.5.1:*:*:*:*:*:*:*
cpe:2.3:a:ez:ez_publish:3.5.2:*:*:*:*:*:*:*
cpe:2.3:a:ez:ez_publish:3.5.3:*:*:*:*:*:*:*
cpe:2.3:a:ez:ez_publish:3.5.4:*:*:*:*:*:*:*
cpe:2.3:a:ez:ez_publish:3.5.5:*:*:*:*:*:*:*
cpe:2.3:a:ez:ez_publish:3.5.6:*:*:*:*:*:*:*
cpe:2.3:a:ez:ez_publish:3.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ez:ez_publish:3.6.1:*:*:*:*:*:*:*
cpe:2.3:a:ez:ez_publish:3.6.2:*:*:*:*:*:*:*
cpe:2.3:a:ez:ez_publish:3.6.3:*:*:*:*:*:*:*
cpe:2.3:a:ez:ez_publish:3.6.4:*:*:*:*:*:*:*
cpe:2.3:a:ez:ez_publish:3.7.0:*:*:*:*:*:*:*
cpe:2.3:a:ez:ez_publish:3.7.1:*:*:*:*:*:*:*
cpe:2.3:a:ez:ez_publish:3.7.2:*:*:*:*:*:*:*

EPSS

Процентиль: 50%
0.00273
Низкий

5 Medium

CVSS2

Дефекты

CWE-19

Связанные уязвимости

ubuntu
почти 20 лет назад

The admin interface in eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051110 does not properly handle authorization errors, which allows remote attackers to obtain sensitive information and see the admin pagelayout and associated templates via a request with (1) "anything after the url" or (2) a "wrong url".

debian
почти 20 лет назад

The admin interface in eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, ...

github
больше 3 лет назад

The admin interface in eZ publish 3.5 before 3.5.7, 3.6 before 3.6.5, 3.7 before 3.7.3, and 3.8 before 20051110 does not properly handle authorization errors, which allows remote attackers to obtain sensitive information and see the admin pagelayout and associated templates via a request with (1) "anything after the url" or (2) a "wrong url".

EPSS

Процентиль: 50%
0.00273
Низкий

5 Medium

CVSS2

Дефекты

CWE-19
Уязвимость CVE-2005-4856