Show filters
47 Total Results
Displaying 1-10 of 47
Sort by:
Attacker Value
Unknown
CVE-2012-6661
Disclosure Date: November 03, 2014 (last updated October 05, 2023)
Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does not reseed the pseudo-random number generator (PRNG), which makes it easier for remote attackers to guess the value via unspecified vectors. NOTE: this issue was SPLIT from CVE-2012-5508 due to different vulnerability types (ADT2).
0
Attacker Value
Unknown
CVE-2012-5508
Disclosure Date: November 03, 2014 (last updated November 08, 2023)
The error pages in Plone before 4.2.3 and 4.3 before beta 1 allow remote attackers to obtain random numbers and derive the PRNG state for password resets via unspecified vectors. NOTE: this identifier was SPLIT per ADT2 due to different vulnerability types. CVE-2012-6661 was assigned for the PRNG reseeding issue in Zope.
0
Attacker Value
Unknown
CVE-2012-5500
Disclosure Date: November 03, 2014 (last updated October 05, 2023)
The batch id change script (renameObjectsByPaths.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to change the titles of content items by leveraging a valid CSRF token in a crafted request.
0
Attacker Value
Unknown
CVE-2012-5485
Disclosure Date: September 30, 2014 (last updated October 05, 2023)
registerConfiglet.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via unspecified vectors, related to the admin interface.
0
Attacker Value
Unknown
CVE-2012-5490
Disclosure Date: September 30, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in kssdevel.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-5493
Disclosure Date: September 30, 2014 (last updated October 05, 2023)
gtbn.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain permissions to bypass the Python sandbox and execute arbitrary Python code via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-5486
Disclosure Date: September 30, 2014 (last updated October 05, 2023)
ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attackers to inject arbitrary HTTP headers via a linefeed (LF) character.
0
Attacker Value
Unknown
CVE-2012-5496
Disclosure Date: September 30, 2014 (last updated October 05, 2023)
kupu_spellcheck.py in Kupu in Plone before 4.0 allows remote attackers to cause a denial of service (ZServer thread lock) via a crafted URL.
0
Attacker Value
Unknown
CVE-2012-5507
Disclosure Date: September 30, 2014 (last updated October 05, 2023)
AccessControl/AuthEncoding.py in Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain passwords via vectors involving timing discrepancies in password validation.
0
Attacker Value
Unknown
CVE-2012-5494
Disclosure Date: September 30, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to "{u,}translate."
0