Plone

Plone

103 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.82%
  • Veröffentlicht 30.09.2014 14:55:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attackers to inject arbitrary HTTP headers via a linefeed (LF) character.

  • EPSS 0.79%
  • Veröffentlicht 30.09.2014 14:55:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain privileges to bypass the Python sandbox restriction and execute arbitrary Python code via vectors related to...

  • EPSS 0.64%
  • Veröffentlicht 30.09.2014 14:55:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to createObject.

  • EPSS 0.28%
  • Veröffentlicht 02.05.2014 14:55:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Products/CMFPlone/FactoryTool.py in Plone 3.3 through 4.3.2 allows remote attackers to obtain the installation path via vectors related to a file object for unspecified documentation which is initialized in class scope.

  • EPSS 0.26%
  • Veröffentlicht 02.05.2014 14:55:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API.

  • EPSS 0.56%
  • Veröffentlicht 11.03.2014 19:37:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

traverser.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote attackers with administrator privileges to cause a denial of service (infinite loop and resource consumption) via unspecified vectors related to "retrie...

  • EPSS 0.5%
  • Veröffentlicht 11.03.2014 19:37:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple unspecified vulnerabilities in (1) dataitems.py, (2) get.py, and (3) traverseName.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote authenticated users with administrator access to a subtree to access nod...

  • EPSS 0.26%
  • Veröffentlicht 11.03.2014 19:37:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple cross-site scripting (XSS) vulnerabilities in (1) spamProtect.py, (2) pts.py, and (3) request.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote attackers to inject arbitrary web script or HTML via unspeci...

  • EPSS 0.31%
  • Veröffentlicht 11.03.2014 19:37:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

zip.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce access restrictions when including content in a zip archive, which allows remote attackers to obtain sensitive information by reading a generated ...

  • EPSS 0.22%
  • Veröffentlicht 11.03.2014 19:37:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

sendto.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to spoof emails via unspecified vectors.