9.3
CVSSv2

CVE-2011-3587

Published: 10/10/2011 Updated: 21/10/2011
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x up to and including 4.0.9, 4.1, and 4.2 up to and including 4.2a2, allows remote malicious users to execute arbitrary commands via vectors related to the p_ class in OFS/misc_.py and the use of Python modules.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zope zope 2.12.9

zope zope 2.12.13

zope zope 2.12.2

zope zope 2.12.0

zope zope 2.12.17

zope zope 2.12.15

zope zope 2.13.0

zope zope 2.13.1

plone plone 4.0.8

plone plone 4.0.1

plone plone 4.1

plone plone 4.2

zope zope 2.12.12

zope zope 2.12.14

zope zope 2.12.18

zope zope 2.12.6

zope zope 2.13.2

zope zope 2.12.19

zope zope 2.12.20

plone plone 4.0.3

plone plone 4.0.2

plone plone 4.2a2

plone plone 4.2a1

zope zope 2.12.4

zope zope 2.12.8

zope zope 2.12.11

zope zope 2.12.5

zope zope 2.12.7

zope zope 2.13.5

zope zope 2.13.10

plone plone 4.0.7

plone plone 4.0

plone plone 4.0.9

zope zope 2.12.3

zope zope 2.12.10

zope zope 2.12.1

zope zope 2.12.16

zope zope 2.13.7

zope zope 2.13.6

zope zope 2.13.4

zope zope 2.13.3

zope zope 2.13.8

zope zope 2.13.9

plone plone 4.0.5

plone plone 4.0.4

plone plone 4.0.6.1

Exploits

# Exploit Title: Plone - Remote Command Execution # Date: 12/21/2011 # Author: Nick Miles (wwwnpenetrablecom) # Tested on: 12/21/2011 # CVE : CVE-2011-3587 Versions Affected (without hotfix): Plone 40 (through 409); Plone 41; Plone 42 (a1 and a2); Zope 212x and Zope 213x Versions Not Affected: Versions of Plone that use Zope other than ...
Proof of concept code that demonstrates a remote command execution in Plone versions 40 through 409, 41, 42 (a1 and a2) and Zope versions 212x and 213x ...