The admin interface in eZ publish 3.5 prior to 3.5.7, 3.6 prior to 3.6.5, 3.7 prior to 3.7.3, and 3.8 prior to 20051110 does not properly handle authorization errors, which allows remote malicious users to obtain sensitive information and see the admin pagelayout and associated templates via a request with (1) "anything after the url" or (2) a "wrong url".
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ez ez publish 3.5.0 |
||
ez ez publish 3.5.1 |
||
ez ez publish 3.7.2 |
||
ez ez publish |
||
ez ez publish 3.5.6 |
||
ez ez publish 3.6.0 |
||
ez ez publish 3.6.1 |
||
ez ez publish 3.6.2 |
||
ez ez publish 3.5.3 |
||
ez ez publish 3.5.5 |
||
ez ez publish 3.6.3 |
||
ez ez publish 3.7.0 |
||
ez ez publish 3.5.2 |
||
ez ez publish 3.5.4 |
||
ez ez publish 3.6.4 |
||
ez ez publish 3.7.1 |