CVE detail
CVE-2005-4855 — CVE-2005-4855
Published 2005-12-31 · Modified 2026-06-16 · Vendor ez · Product ez_publish · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0073
EPSS probability
exploitation probability, 30d
51.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Unrestricted file upload vulnerability in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050922 does not restrict Image datatype uploads to image content types, which allows remote authenticated users to upload certain types of files, as demonstrated by .js files, which may enable cross-site scripting (XSS) attacks or other attacks.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References