CVE-2005-4851
Published Dec 31, 2005
Last updated 5 years ago
Overview
- Description
- eZ publish 3.4.4 through 3.7 before 20050722 applies certain permissions on the node level, which allows remote authenticated users to bypass the original permissions on embedded objects in XML fields and read these objects.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4
- Impact score
- 2.9
- Exploitability score
- 8
- Vector string
- AV:N/AC:L/Au:S/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-287
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ez:ez_publish:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6113B7A4-15F3-4901-8B51-2C1BEBA23006", "versionEndIncluding": "3.7", "versionStartIncluding": "3.4.4" } ], "operator": "OR" } ] } ]