CVE Vulnerabilities

CVE-2005-3765

Published: Nov 22, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Exponent CMS 0.96.3 and later versions performs a chmod on uploaded files to give them execute permissions, which allows remote attackers to execute arbitrary code.

Affected Software

NameVendorStart VersionEnd Version
ExponentExponent0.94 (including)0.94 (including)
ExponentExponent0.95 (including)0.95 (including)
ExponentExponent0.96.1 (including)0.96.1 (including)
ExponentExponent0.96.3 (including)0.96.3 (including)
ExponentExponent0.96.4 (including)0.96.4 (including)

References