← All CVEs

CVE-2011-3587

high · 9.3

Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to execute arbitrary commands via vectors related to the p_ class in OFS/misc_.py and the use of Python modules.

9.3
CVSS
78.1%
EPSS (exploit prob.)
100th
EPSS percentile
2011-10-10
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

VendorProductAffected versions
ploneplone4.0
ploneplone4.0.1
ploneplone4.0.2
ploneplone4.0.3
ploneplone4.0.4
ploneplone4.0.5
ploneplone4.0.6.1
ploneplone4.0.7
ploneplone4.0.8
ploneplone4.0.9
ploneplone4.1
ploneplone4.2
ploneplone4.2a1
ploneplone4.2a2
zopezope2.12.0
zopezope2.12.0
zopezope2.12.0
zopezope2.12.0
zopezope2.12.0
zopezope2.12.0
zopezope2.12.0
zopezope2.12.0
zopezope2.12.0
zopezope2.12.1
zopezope2.12.2
zopezope2.12.3
zopezope2.12.4
zopezope2.12.5
zopezope2.12.6
zopezope2.12.7
zopezope2.12.8
zopezope2.12.9
zopezope2.12.10
zopezope2.12.11
zopezope2.12.12
zopezope2.12.13
zopezope2.12.14
zopezope2.12.15
zopezope2.12.16
zopezope2.12.17

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2011-3587