Vulnerability CVE-2005-3764


Published: 2005-11-22   Modified: 2012-02-12

Description:
The image gallery (imagegallery) component in Exponent CMS 0.96.3 and later versions does not properly check the MIME type of uploaded files, with unknown impact from the preview icon, possibly involving injection of HTML.

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Exponent -> Exponent 

 References:
http://www.securityfocus.com/archive/1/417218
http://secunia.com/advisories/17655

Copyright 2024, cxsecurity.com

 

Back to Top