CVE Vulnerabilities

CVE-2005-3764

Published: Nov 22, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The image gallery (imagegallery) component in Exponent CMS 0.96.3 and later versions does not properly check the MIME type of uploaded files, with unknown impact from the preview icon, possibly involving injection of HTML.

Affected Software

NameVendorStart VersionEnd Version
ExponentExponent0.94 (including)0.94 (including)
ExponentExponent0.95 (including)0.95 (including)
ExponentExponent0.96.1 (including)0.96.1 (including)
ExponentExponent0.96.3 (including)0.96.3 (including)
ExponentExponent0.96.4 (including)0.96.4 (including)

References