CVE Vulnerabilities

CVE-2007-4494

Published: Aug 23, 2007 | Modified: Jul 27, 2015
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

The tipafriend function in eZ publish before 3.8.9, and 3.9 before 3.9.3, does not limit access by anonymous users, which allows remote attackers to conduct spam attacks.

Affected Software

Name Vendor Start Version End Version
Ez_publish Ez * 3.8.8 (including)
Ez_publish Ez 3.9.0 (including) 3.9.0 (including)
Ez_publish Ez 3.9.1 (including) 3.9.1 (including)
Ez_publish Ez 3.9.2 (including) 3.9.2 (including)
Ezpublish Ubuntu dapper *
Ezpublish Ubuntu edgy *
Ezpublish Ubuntu feisty *
Ezpublish Ubuntu gutsy *

References