VYPR
Unrated severityNVD Advisory· Published Nov 22, 2005· Updated Apr 16, 2026

CVE-2005-3764

CVE-2005-3764

Description

The image gallery (imagegallery) component in Exponent CMS 0.96.3 and later versions does not properly check the MIME type of uploaded files, with unknown impact from the preview icon, possibly involving injection of HTML.

Affected products

5
  • Exponent/Exponent5 versions
    cpe:2.3:a:exponent:exponent:0.94:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:exponent:exponent:0.94:*:*:*:*:*:*:*
    • cpe:2.3:a:exponent:exponent:0.95:*:*:*:*:*:*:*
    • cpe:2.3:a:exponent:exponent:0.96.1:*:*:*:*:*:*:*
    • cpe:2.3:a:exponent:exponent:0.96.3:*:*:*:*:*:*:*
    • cpe:2.3:a:exponent:exponent:0.96.4:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.