Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-7219

Опубликовано: 06 июл. 2007
Источник: nvd
CVSS2: 4
EPSS Низкий

Описание

eZ publish before 3.8.5 does not properly enforce permissions for editing in a specific language, which allows remote authenticated users to create a draft in an unauthorized language by editing an archived version of an object, and then using Manage Versions to copy this version to a new draft.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ez:ez_publish:*:*:*:*:*:*:*:*
Версия до 3.8.4 (включая)

EPSS

Процентиль: 37%
0.0016
Низкий

4 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
около 18 лет назад

eZ publish before 3.8.5 does not properly enforce permissions for editing in a specific language, which allows remote authenticated users to create a draft in an unauthorized language by editing an archived version of an object, and then using Manage Versions to copy this version to a new draft.

debian
около 18 лет назад

eZ publish before 3.8.5 does not properly enforce permissions for edit ...

github
больше 3 лет назад

eZ publish before 3.8.5 does not properly enforce permissions for editing in a specific language, which allows remote authenticated users to create a draft in an unauthorized language by editing an archived version of an object, and then using Manage Versions to copy this version to a new draft.

EPSS

Процентиль: 37%
0.0016
Низкий

4 Medium

CVSS2

Дефекты

CWE-264