ID |
CVE-2005-4853
|
Sažetak |
The default configuration of the forum package in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050818 does not restrict edit permissions to a posting's owner, which allows remote authenticated users to edit arbitrary postings. |
Reference |
|
CVSS |
Base: | 9.4 |
Impact: | 9.2 |
Exploitability: | 10.0 |
|
Pristup |
Vektor | Složenost | Autentikacija |
NETWORK |
LOW |
NONE |
|
Impact |
Povjerljivost | Cjelovitost | Dostupnost |
NONE |
COMPLETE |
COMPLETE |
|
CVSS vektor |
AV:N/AC:L/Au:N/C:N/I:C/A:C |
Zadnje važnije ažuriranje |
28-07-2015 - 14:41 |
Objavljeno |
31-12-2005 - 05:00 |