CVE-2006-7218

eZ publish before 3.8.1 does not properly enforce permissions for "content edit Language" when there are four or more languages, which allows remote authenticated users to perform translations into languages that are not listed in a Module Function Limitation policy.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:ez:ez_publish:*:*:*:*:*:*:*:*

Information

Published : 2007-07-06 12:30

Updated : 2015-07-28 07:35


NVD link : CVE-2006-7218

Mitre link : CVE-2006-7218


JSON object : View

CWE
CWE-264

Permissions, Privileges, and Access Controls

Advertisement

dedicated server usa

Products Affected

ez

  • ez_publish