First published: Tue Nov 22 2005(Updated: )
The image gallery (imagegallery) component in Exponent CMS 0.96.3 and later versions does not properly check the MIME type of uploaded files, with unknown impact from the preview icon, possibly involving injection of HTML.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Exponent Exponent | =0.94 | |
Exponent Exponent | =0.96.3 | |
Exponent Exponent | =0.96.1 | |
Exponent Exponent | =0.95 | |
Exponent Exponent | =0.96.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3764 is classified as a moderate severity vulnerability due to its potential for HTML injection.
To fix CVE-2005-3764, update Exponent CMS to the latest version that includes a proper MIME type check for uploaded files.
CVE-2005-3764 affects Exponent CMS versions 0.94, 0.95, 0.96.1, 0.96.3, and 0.96.4.
CVE-2005-3764 potentially allows for HTML injection through improperly verified MIME types of uploaded files.
A potential workaround for CVE-2005-3764 is to disable file uploads until an update can be applied.