Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2012-5486

Disclosure Date: September 30, 2014 (last updated October 05, 2023)
ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attackers to inject arbitrary HTTP headers via a linefeed (LF) character.
0
Attacker Value
Unknown

CVE-2012-5507

Disclosure Date: September 30, 2014 (last updated October 05, 2023)
AccessControl/AuthEncoding.py in Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain passwords via vectors involving timing discrepancies in password validation.
0
Attacker Value
Unknown

CVE-2012-5489

Disclosure Date: September 30, 2014 (last updated October 05, 2023)
The App.Undo.UndoSupport.get_request_var_or_attr function in Zope before 2.12.21 and 3.13.x before 2.13.11, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote authenticated users to gain access to restricted attributes via unspecified vectors.
0
Attacker Value
Unknown

CVE-2010-3198

Disclosure Date: September 08, 2010 (last updated October 04, 2023)
ZServer in Zope 2.10.x before 2.10.12 and 2.11.x before 2.11.7 allows remote attackers to cause a denial of service (crash of worker threads) via vectors that trigger uncaught exceptions.
0
Attacker Value
Unknown

CVE-2010-1104

Disclosure Date: March 25, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3 allows remote attackers to inject arbitrary web script or HTML via vectors related to error messages.
0