« Volver al listado

CVE-2007-4494

Estado: ModificadaMedia (5)—

The tipafriend function in eZ publish before 3.8.9, and 3.9 before 3.9.3, does not limit access by anonymous users, which allows remote attackers to conduct spam attacks.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-4494",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-08-23T01:17:00.000",
  "references": [
    {
      "url": "http://ez.no/community/news/ez_publish_security_fixes_3_9_3_and_3_8_9",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://ez.no/download/ez_publish/changelogs/ez_publish_3_8/changelog_3_8_8_to_3_8_9",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://ez.no/download/ez_publish/changelogs/ez_publish_3_9/changelog_3_9_2_to_3_9_3",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/40325",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/26686",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/25538",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://ez.no/community/news/ez_publish_security_fixes_3_9_3_and_3_8_9",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://ez.no/download/ez_publish/changelogs/ez_publish_3_8/changelog_3_8_8_to_3_8_9",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://ez.no/download/ez_publish/changelogs/ez_publish_3_9/changelog_3_9_2_to_3_9_3",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/40325",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/26686",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/25538",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The tipafriend function in eZ publish before 3.8.9, and 3.9 before 3.9.3, does not limit access by anonymous users, which allows remote attackers to conduct spam attacks."
    },
    {
      "lang": "es",
      "value": "La función tipafriend en eZ publish anterior a 3.8.9, y 3.9 anterior a 3.9.3, no limita el acceso a usuarios anónimos, lo cual permite a atacantes remotos llevar a cabo ataques de spam (correo electrónico no deseado)."
    }
  ],
  "lastModified": "2026-06-16T22:44:12.253",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ez:ez_publish:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "188CAEF6-A825-4362-86F5-929E2F595010",
              "versionEndIncluding": "3.8.8"
            },
            {
              "criteria": "cpe:2.3:a:ez:ez_publish:3.9.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C76B152B-FE9D-47A5-B011-066814F72953"
            },
            {
              "criteria": "cpe:2.3:a:ez:ez_publish:3.9.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "77519B1C-CB4E-4239-81AA-5C1CDE81A45B"
            },
            {
              "criteria": "cpe:2.3:a:ez:ez_publish:3.9.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A4F62153-7A64-44C1-ABE7-68D4628DEE38"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}