8.5
CVSSv2

CVE-2012-5487

Published: 30/09/2014 Updated: 01/10/2014
CVSS v2 Base Score: 8.5 | Impact Score: 10 | Exploitability Score: 6.8
VMScore: 756
Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Summary

The sandbox whitelisting function (allowmodule.py) in Plone prior to 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain privileges to bypass the Python sandbox restriction and execute arbitrary Python code via vectors related to importing.

Vulnerable Product Search on Vulmon Subscribe to Product

plone plone 1.0

plone plone 1.0.1

plone plone 1.0.2

plone plone 2.1.2

plone plone 2.1.3

plone plone 2.1.4

plone plone 2.5

plone plone 3.1.1

plone plone 3.1.2

plone plone 3.1.3

plone plone 3.1.4

plone plone 4.0

plone plone 4.0.1

plone plone 4.0.2

plone plone 4.0.3

plone plone 4.2

plone plone 4.2.0.1

plone plone 4.2.1.1

plone plone 4.2.1

plone plone 2.0

plone plone 2.0.1

plone plone 2.0.2

plone plone 2.0.3

plone plone 3.0

plone plone 3.0.1

plone plone 3.0.2

plone plone 3.0.3

plone plone 3.2.1

plone plone 3.2.2

plone plone 3.2.3

plone plone 3.3

plone plone 4.1.4

plone plone 4.1.5

plone plone 4.1.6

plone plone 1.0.4

plone plone 1.0.6

plone plone 2.0.4

plone plone 2.1

plone plone 2.5.2

plone plone 2.5.4

plone plone 3.0.5

plone plone 3.1

plone plone 3.1.5.1

plone plone 3.1.7

plone plone 3.3.2

plone plone 3.3.4

plone plone 4.0.5

plone plone 4.1

plone plone

plone plone 1.0.3

plone plone 1.0.5

plone plone 2.0.5

plone plone 2.1.1

plone plone 2.5.1

plone plone 2.5.3

plone plone 2.5.5

plone plone 3.0.4

plone plone 3.0.6

plone plone 3.1.6

plone plone 3.2

plone plone 3.3.1

plone plone 3.3.3

plone plone 3.3.5

plone plone 4.0.4

plone plone 4.0.6.1

plone plone 4.3