CVE Vulnerabilities

CVE-2005-3765

Published: Nov 22, 2005 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Exponent CMS 0.96.3 and later versions performs a chmod on uploaded files to give them execute permissions, which allows remote attackers to execute arbitrary code.

Affected Software

Name Vendor Start Version End Version
Exponent Exponent 0.94 (including) 0.94 (including)
Exponent Exponent 0.95 (including) 0.95 (including)
Exponent Exponent 0.96.1 (including) 0.96.1 (including)
Exponent Exponent 0.96.3 (including) 0.96.3 (including)
Exponent Exponent 0.96.4 (including) 0.96.4 (including)

References