Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-7218

Опубликовано: 06 июл. 2007
Источник: nvd
CVSS2: 4
EPSS Низкий

Описание

eZ publish before 3.8.1 does not properly enforce permissions for "content edit Language" when there are four or more languages, which allows remote authenticated users to perform translations into languages that are not listed in a Module Function Limitation policy.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ez:ez_publish:*:*:*:*:*:*:*:*
Версия до 3.8.0 (включая)

EPSS

Процентиль: 37%
0.0016
Низкий

4 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
около 18 лет назад

eZ publish before 3.8.1 does not properly enforce permissions for "content edit Language" when there are four or more languages, which allows remote authenticated users to perform translations into languages that are not listed in a Module Function Limitation policy.

debian
около 18 лет назад

eZ publish before 3.8.1 does not properly enforce permissions for "con ...

github
больше 3 лет назад

eZ publish before 3.8.1 does not properly enforce permissions for "content edit Language" when there are four or more languages, which allows remote authenticated users to perform translations into languages that are not listed in a Module Function Limitation policy.

EPSS

Процентиль: 37%
0.0016
Низкий

4 Medium

CVSS2

Дефекты

CWE-264