J-Security Center

Title: EZ Publish Multiple Path Disclosure Vulnerabilities

Severity: MODERATE

Description:

eZ Publish is a web content management system for Microsoft Windows and Unix and Linux variants.

Several path disclosure vulnerabilities have been reported for eZ Publish. The vulnerabilities affect several PHP script files in the kernel/class and kernel/classes directory.

An attacker can exploit this vulnerability by making a HTTP request for any of the affected pages. This may result in a condition where path information is returned to the attacker. Information gathered in this way may be used in further attacks against the system.

This vulnerability affects eZ Publish 3.0. It is likely that earlier versions are also affected.

Affected Products:

  • eZ Systems eZ publish 2.2.7
  • eZ Systems eZ publish 3.0.0

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.