CVE-2011-3587
high · 9.3Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to execute arbitrary commands via vectors related to the p_ class in OFS/misc_.py and the use of Python modules.
9.3
CVSS
78.1%
EPSS (exploit prob.)
100th
EPSS percentile
2011-10-10
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| plone | plone | 4.0 |
| plone | plone | 4.0.1 |
| plone | plone | 4.0.2 |
| plone | plone | 4.0.3 |
| plone | plone | 4.0.4 |
| plone | plone | 4.0.5 |
| plone | plone | 4.0.6.1 |
| plone | plone | 4.0.7 |
| plone | plone | 4.0.8 |
| plone | plone | 4.0.9 |
| plone | plone | 4.1 |
| plone | plone | 4.2 |
| plone | plone | 4.2a1 |
| plone | plone | 4.2a2 |
| zope | zope | 2.12.0 |
| zope | zope | 2.12.0 |
| zope | zope | 2.12.0 |
| zope | zope | 2.12.0 |
| zope | zope | 2.12.0 |
| zope | zope | 2.12.0 |
| zope | zope | 2.12.0 |
| zope | zope | 2.12.0 |
| zope | zope | 2.12.0 |
| zope | zope | 2.12.1 |
| zope | zope | 2.12.2 |
| zope | zope | 2.12.3 |
| zope | zope | 2.12.4 |
| zope | zope | 2.12.5 |
| zope | zope | 2.12.6 |
| zope | zope | 2.12.7 |
| zope | zope | 2.12.8 |
| zope | zope | 2.12.9 |
| zope | zope | 2.12.10 |
| zope | zope | 2.12.11 |
| zope | zope | 2.12.12 |
| zope | zope | 2.12.13 |
| zope | zope | 2.12.14 |
| zope | zope | 2.12.15 |
| zope | zope | 2.12.16 |
| zope | zope | 2.12.17 |
Check a specific version with /api/v1/cve/match.
References
- http://plone.org/products/plone-hotfix/releases/20110928
- http://plone.org/products/plone-hotfix/releases/20110928/PloneHotfix20110928-1.0.zip
- http://plone.org/products/plone/security/advisories/20110928
- http://pypi.python.org/pypi/Products.PloneHotfix20110928/1.0
- http://secunia.com/advisories/46221
- http://secunia.com/advisories/46323
- http://zope2.zope.org/news/security-vulnerability-announcement-cve-2011-3587
- https://bugzilla.redhat.com/show_bug.cgi?id=742297
- http://plone.org/products/plone-hotfix/releases/20110928
- http://plone.org/products/plone-hotfix/releases/20110928/PloneHotfix20110928-1.0.zip
- http://plone.org/products/plone/security/advisories/20110928
- http://pypi.python.org/pypi/Products.PloneHotfix20110928/1.0
- http://secunia.com/advisories/46221
- http://secunia.com/advisories/46323
- http://zope2.zope.org/news/security-vulnerability-announcement-cve-2011-3587
- https://bugzilla.redhat.com/show_bug.cgi?id=742297
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2011-3587