Vulnerability index

Browse CVEs

87 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Plone MEDIUM 5.0
CVE-2012-5503

ftp.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read hidden folder contents via unspecified vectors.

Fix: after 4.2.2
Fix from $1,600 2014-09-30
Plone MEDIUM 5.0
CVE-2012-5505

atat.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read private data structures via a request for a view without a name.

Fix: after 4.2.2
Fix from $1,600 2014-09-30
Plone MEDIUM 5.0
CVE-2012-5506

python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to cause a denial of service (infinite loop) via an RSS feed re…

Fix: after 4.2.2
Fix from $1,600 2014-09-30
Plone HIGH 8.5
CVE-2012-5487

The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain privile…

Fix: after 4.2.2
Fix from $1,950 2014-09-30
Plone MEDIUM 6.8
CVE-2012-5485

registerConfiglet.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via unspecified vectors, related to t…

Fix: after 4.2.2
Fix from $1,600 2014-09-30
Plone MEDIUM 6.4
CVE-2012-5486

ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attackers to inject arbitrary HTTP he…

Fix: after 4.2.2
Fix from $1,600 2014-09-30
Plone MEDIUM 5.0
CVE-2012-5488

python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to createObje…

Fix: after 4.2.2
Fix from $1,600 2014-09-30
Plone MEDIUM 5.5
CVE-2013-7061

Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via …

Mitigation only
Fix from $1,600 2014-05-02
Plone MEDIUM 5.0
CVE-2013-7060

Products/CMFPlone/FactoryTool.py in Plone 3.3 through 4.3.2 allows remote attackers to obtain the installation path via vectors related to a file obj…

Mitigation only
Fix from $1,600 2014-05-02
Plone MEDIUM 6.5
CVE-2013-4189

Multiple unspecified vulnerabilities in (1) dataitems.py, (2) get.py, and (3) traverseName.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.…

Patch available
Fix from $1,600 2014-03-11
Plone MEDIUM 5.8
CVE-2013-4191

zip.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce access restrictions when including content in…

Patch available
Fix from $1,600 2014-03-11
Plone MEDIUM 5.8
CVE-2013-4195

Multiple open redirect vulnerabilities in (1) marmoset_patch.py, (2) publish.py, and (3) principiaredirect.py in Plone 2.1 through 4.1, 4.2.x through…

Patch available
Fix from $1,600 2014-03-11
Plone MEDIUM 5.5
CVE-2013-4197

member_portrait.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to modify or delete portr…

Patch available
Fix from $1,600 2014-03-11
Plone MEDIUM 5.0
CVE-2013-4196

The object manager implementation (objectmanager.py) in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly restric…

Patch available
Fix from $1,600 2014-03-11
Plone MEDIUM 5.8
CVE-2013-4200

The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 treats URLs star…

Patch available
Fix from $1,600 2014-01-21
Plone MEDIUM 5.0
CVE-2011-4462

Plone 4.1.3 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows…

Fix: after 4.1.3
Fix from $1,600 2011-12-30
Plone HIGH 9.3
CVE-2011-3587EPSS 78%

Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to exe…

Patch available
Fix from $1,950 2011-10-10
Cmfeditions HIGH 9.3
CVE-2011-4030

The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publish…

Patch available
Fix from $1,950 2011-10-10
Plone Hotfix 20110720 HIGH 7.5
CVE-2011-2528

Unspecified vulnerability in (1) Zope 2.12.x before 2.12.19 and 2.13.x before 2.13.8, as used in Plone 4.x and other products, and (2) PloneHotfix201…

Patch available
Fix from $1,950 2011-07-19
Plone MEDIUM 5.5
CVE-2011-1950

plone.app.users in Plone 4.0 and 4.1 allows remote authenticated users to modify the properties of arbitrary accounts via unspecified vectors, as exp…

Patch available
Fix from $1,600 2011-06-06
Plonepas MEDIUM 6.0
CVE-2009-0662

The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authent…

Patch available
Fix from $1,600 2009-04-23
Plone Cms HIGH 10.0
CVE-2008-1393

Plone CMS 3.0.5, and probably other 3.x versions, places a base64 encoded form of the username and password in the __ac cookie for the admin account,…

Fix: after 3.0.5
Fix from $1,950 2008-03-20
Plone Cms HIGH 7.5
CVE-2008-1394

Plone CMS before 3 places a base64 encoded form of the username and password in the __ac cookie for all user accounts, which makes it easier for remo…

Fix: after 2.5.1
Fix from $1,950 2008-03-20
Plone Cms HIGH 7.5
CVE-2008-1395

Plone CMS does not record users' authentication states, and implements the logout feature solely on the client side, which makes it easier for contex…

Mitigation only
Fix from $1,950 2008-03-20
Plone HIGH 7.5
CVE-2007-5741

Plone 2.5 through 2.5.4 and 3.0 through 3.0.2 allows remote attackers to execute arbitrary Python code via network data containing pickled objects fo…

Patch available
Fix from $1,950 2007-11-07
Plone MEDIUM 6.4
CVE-2006-4247

Unspecified vulnerability in the Password Reset Tool before 0.4.1 on Plone 2.5 and 2.5.1 Release Candidate allows attackers to reset the passwords of…

Patch available
Fix from $1,600 2006-09-29
Plone MEDIUM 5.0
CVE-2006-1711

Plone 2.0.5, 2.1.2, and 2.5-beta1 does not restrict access to the (1) changeMemberPortrait, (2) deletePersonalPortrait, and (3) testCurrentPassword m…

Mitigation only
Fix from $1,600 2006-04-11