Unrated severityNVD Advisory· Published Dec 31, 2005· Updated Apr 16, 2026
CVE-2005-4855
CVE-2005-4855
Description
Unrestricted file upload vulnerability in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050922 does not restrict Image datatype uploads to image content types, which allows remote authenticated users to upload certain types of files, as demonstrated by .js files, which may enable cross-site scripting (XSS) attacks or other attacks.
Affected products
3cpe:2.3:a:ez:ez_publish:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:ez:ez_publish:*:*:*:*:*:*:*:*range: >=3.5.0,<3.5.5
- cpe:2.3:a:ez:ez_publish:3.7.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:ez:ez_publish:3.8.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- ez.no/download/ez_publish/changelogs/ez_publish_3_8/changelog_3_6_x_3_7_x_to_3_8_0nvdVendor Advisory
- issues.ez.no/5984nvdVendor Advisory
News mentions
0No linked articles in our index yet.