Show filters
60 Total Results
Displaying 41-50 of 60
Sort by:
Attacker Value
Unknown
CVE-2013-7061
Disclosure Date: May 02, 2014 (last updated October 05, 2023)
Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API.
0
Attacker Value
Unknown
CVE-2013-4188
Disclosure Date: March 11, 2014 (last updated October 05, 2023)
traverser.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote attackers with administrator privileges to cause a denial of service (infinite loop and resource consumption) via unspecified vectors related to "retrieving information for certain resources."
0
Attacker Value
Unknown
CVE-2013-4190
Disclosure Date: March 11, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in (1) spamProtect.py, (2) pts.py, and (3) request.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-4189
Disclosure Date: March 11, 2014 (last updated October 05, 2023)
Multiple unspecified vulnerabilities in (1) dataitems.py, (2) get.py, and (3) traverseName.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote authenticated users with administrator access to a subtree to access nodes above the subtree via unknown vectors.
0
Attacker Value
Unknown
CVE-2013-4196
Disclosure Date: March 11, 2014 (last updated October 05, 2023)
The object manager implementation (objectmanager.py) in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly restrict access to internal methods, which allows remote attackers to obtain sensitive information via a crafted request.
0
Attacker Value
Unknown
CVE-2013-4195
Disclosure Date: March 11, 2014 (last updated October 05, 2023)
Multiple open redirect vulnerabilities in (1) marmoset_patch.py, (2) publish.py, and (3) principiaredirect.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-4198
Disclosure Date: March 11, 2014 (last updated October 05, 2023)
mail_password.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to bypass the prohibition on password changes via the forgotten password email functionality.
0
Attacker Value
Unknown
CVE-2013-4197
Disclosure Date: March 11, 2014 (last updated October 05, 2023)
member_portrait.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to modify or delete portraits of other users via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-4193
Disclosure Date: March 11, 2014 (last updated October 05, 2023)
typeswidget.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce the immutable setting on unspecified content edit forms, which allows remote attackers to hide fields on the forms via a crafted URL.
0
Attacker Value
Unknown
CVE-2013-4191
Disclosure Date: March 11, 2014 (last updated October 05, 2023)
zip.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce access restrictions when including content in a zip archive, which allows remote attackers to obtain sensitive information by reading a generated archive.
0