CVE Vulnerabilities

CVE-2005-3767

Published: Nov 22, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Exponent CMS 0.96.3 and later versions does not properly restrict the types of uploaded files, which allows remote attackers to upload and execute PHP files.

Affected Software

NameVendorStart VersionEnd Version
ExponentExponent0.94 (including)0.94 (including)
ExponentExponent0.95 (including)0.95 (including)
ExponentExponent0.96.1 (including)0.96.1 (including)
ExponentExponent0.96.3 (including)0.96.3 (including)
ExponentExponent0.96.4 (including)0.96.4 (including)

References