← Back

CVE-2007-4494

nvd nist
Published: Aug 23, 2007Modified: Apr 23, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The tipafriend function in eZ publish before 3.8.9, and 3.9 before 3.9.3, does not limit access by anonymous users, which allows remote attackers to conduct spam attacks.

Affected (4)

Products: Ez: Ez Publish
1 product
Ez Publish
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Ez
Up to 3.8.8
Version 3.9.0
Version 3.9.1
Version 3.9.2

Timeline

No history available yet.