Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2012-6661
Disclosure Date: November 03, 2014 (last updated October 05, 2023)
Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does not reseed the pseudo-random number generator (PRNG), which makes it easier for remote attackers to guess the value via unspecified vectors. NOTE: this issue was SPLIT from CVE-2012-5508 due to different vulnerability types (ADT2).
0
Attacker Value
Unknown
CVE-2012-5486
Disclosure Date: September 30, 2014 (last updated October 05, 2023)
ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attackers to inject arbitrary HTTP headers via a linefeed (LF) character.
0
Attacker Value
Unknown
CVE-2012-5507
Disclosure Date: September 30, 2014 (last updated October 05, 2023)
AccessControl/AuthEncoding.py in Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain passwords via vectors involving timing discrepancies in password validation.
0
Attacker Value
Unknown
CVE-2012-5489
Disclosure Date: September 30, 2014 (last updated October 05, 2023)
The App.Undo.UndoSupport.get_request_var_or_attr function in Zope before 2.12.21 and 3.13.x before 2.13.11, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote authenticated users to gain access to restricted attributes via unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-5102
Disclosure Date: November 17, 2008 (last updated October 04, 2023)
PythonScripts in Zope 2 2.11.2 and earlier, as used in Conga and other products, allows remote authenticated users to cause a denial of service (resource consumption or application halt) via certain (1) raise or (2) import statements.
0