Логотип exploitDog
bind:CVE-2005-4855
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2005-4855

Количество 4

Количество 4

ubuntu логотип

CVE-2005-4855

больше 19 лет назад

Unrestricted file upload vulnerability in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050922 does not restrict Image datatype uploads to image content types, which allows remote authenticated users to upload certain types of files, as demonstrated by .js files, which may enable cross-site scripting (XSS) attacks or other attacks.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2005-4855

больше 19 лет назад

Unrestricted file upload vulnerability in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050922 does not restrict Image datatype uploads to image content types, which allows remote authenticated users to upload certain types of files, as demonstrated by .js files, which may enable cross-site scripting (XSS) attacks or other attacks.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2005-4855

больше 19 лет назад

Unrestricted file upload vulnerability in eZ publish 3.5 before 3.5.5, ...

CVSS2: 3.5
EPSS: Низкий
github логотип

GHSA-q58x-g5cp-qvh7

больше 3 лет назад

Unrestricted file upload vulnerability in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050922 does not restrict Image datatype uploads to image content types, which allows remote authenticated users to upload certain types of files, as demonstrated by .js files, which may enable cross-site scripting (XSS) attacks or other attacks.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2005-4855

Unrestricted file upload vulnerability in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050922 does not restrict Image datatype uploads to image content types, which allows remote authenticated users to upload certain types of files, as demonstrated by .js files, which may enable cross-site scripting (XSS) attacks or other attacks.

CVSS2: 3.5
0%
Низкий
больше 19 лет назад
nvd логотип
CVE-2005-4855

Unrestricted file upload vulnerability in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050922 does not restrict Image datatype uploads to image content types, which allows remote authenticated users to upload certain types of files, as demonstrated by .js files, which may enable cross-site scripting (XSS) attacks or other attacks.

CVSS2: 3.5
0%
Низкий
больше 19 лет назад
debian логотип
CVE-2005-4855

Unrestricted file upload vulnerability in eZ publish 3.5 before 3.5.5, ...

CVSS2: 3.5
0%
Низкий
больше 19 лет назад
github логотип
GHSA-q58x-g5cp-qvh7

Unrestricted file upload vulnerability in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050922 does not restrict Image datatype uploads to image content types, which allows remote authenticated users to upload certain types of files, as demonstrated by .js files, which may enable cross-site scripting (XSS) attacks or other attacks.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу