Release date: 2012-10-08
Updated on: 2012-10-09
Affected Systems:
EZ Systems eZ Publish 4.6
EZ Systems eZ Publish 4.5
EZ Systems eZ Publish 4.4
EZ Systems eZ Publish 4.3
EZ Systems eZ Publish 4.2
EZ Systems eZ Publish 4.1.4
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52516
Cve id: CVE-2012-1565
EZ Publish is an enterprise-level network content management system.
EZ Publish 4.1.4, 4.2, 4.3, 4.4, 4.5, and 4.6 have security vulnerabilities, which may cause direct object reference-related attacks. The details are unknown.
<* Source: Oppida
Link: http://secunia.com/advisories/48338
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
EZ Systems
----------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://developer.ez.no/