Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 53 251

Количество 53 251

redhat логотип

CVE-2012-5500

почти 14 лет назад

The batch id change script (renameObjectsByPaths.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to change the titles of content items by leveraging a valid CSRF token in a crafted request.

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2012-5499

почти 14 лет назад

python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to cause a denial of service (memory consumption) via a large value, related to formatColumns.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2012-5498

почти 14 лет назад

queryCatalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to bypass caching and cause a denial of service via a crafted request to a collection.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2012-5497

почти 14 лет назад

membership_tool.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to enumerate user account names via a crafted URL.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2012-5496

почти 14 лет назад

kupu_spellcheck.py in Kupu in Plone before 4.0 allows remote attackers to cause a denial of service (ZServer thread lock) via a crafted URL.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2012-5495

почти 14 лет назад

python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to "go_back."

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2012-5494

почти 14 лет назад

Cross-site scripting (XSS) vulnerability in python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to "{u,}translate."

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-5493

почти 14 лет назад

gtbn.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain permissions to bypass the Python sandbox and execute arbitrary Python code via unspecified vectors.

CVSS2: 6
EPSS: Низкий
redhat логотип

CVE-2012-5492

почти 14 лет назад

uid_catalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to obtain metadata about hidden objects via a crafted URL.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-5491

почти 14 лет назад

z3c.form, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain the default form field values by leveraging knowledge of the form location and the element id.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-5490

почти 14 лет назад

Cross-site scripting (XSS) vulnerability in kssdevel.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-5489

почти 14 лет назад

The App.Undo.UndoSupport.get_request_var_or_attr function in Zope before 2.12.21 and 3.13.x before 2.13.11, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote authenticated users to gain access to restricted attributes via unspecified vectors.

CVSS2: 3.6
EPSS: Низкий
redhat логотип

CVE-2012-5488

почти 14 лет назад

python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to createObject.

CVSS2: 4.6
EPSS: Низкий
redhat логотип

CVE-2012-5487

почти 14 лет назад

The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain privileges to bypass the Python sandbox restriction and execute arbitrary Python code via vectors related to importing.

CVSS2: 6
EPSS: Низкий
redhat логотип

CVE-2012-5486

почти 14 лет назад

ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attackers to inject arbitrary HTTP headers via a linefeed (LF) character.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2012-5485

почти 14 лет назад

registerConfiglet.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via unspecified vectors, related to the admin interface.

CVSS2: 6
EPSS: Низкий
redhat логотип

CVE-2012-5484

больше 13 лет назад

The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2012-5478

больше 13 лет назад

The AuthorizationInterceptor in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 does not properly restrict access, which allows remote authenticated users to bypass intended role restrictions and perform arbitrary JMX operations via unspecified vectors.

CVSS2: 4.9
EPSS: Низкий
redhat логотип

CVE-2012-5390

почти 14 лет назад

The standard universe shadow (condor_shadow.std) component in Condor 7.7.3 through 7.7.6, 7.8.0 before 7.8.5, and 7.9.0 does no properly check privileges, which allows remote attackers to gain privileges via a crafted standard universe job.

CVSS2: 6
EPSS: Низкий
redhat логотип

CVE-2012-5375

больше 13 лет назад

The CRC32C feature in the Btrfs implementation in the Linux kernel before 3.8-rc1 allows local users to cause a denial of service (prevention of file creation) by leveraging the ability to write to a directory important to the victim, and creating a file with a crafted name that is associated with a specific CRC32C hash value.

CVSS2: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2012-5500

The batch id change script (renameObjectsByPaths.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to change the titles of content items by leveraging a valid CSRF token in a crafted request.

CVSS2: 2.6
1%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5499

python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to cause a denial of service (memory consumption) via a large value, related to formatColumns.

CVSS2: 5
2%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5498

queryCatalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to bypass caching and cause a denial of service via a crafted request to a collection.

CVSS2: 5
3%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5497

membership_tool.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to enumerate user account names via a crafted URL.

CVSS2: 5
2%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5496

kupu_spellcheck.py in Kupu in Plone before 4.0 allows remote attackers to cause a denial of service (ZServer thread lock) via a crafted URL.

CVSS2: 5
2%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5495

python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to "go_back."

CVSS2: 5
2%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5494

Cross-site scripting (XSS) vulnerability in python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to "{u,}translate."

CVSS2: 4.3
1%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5493

gtbn.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain permissions to bypass the Python sandbox and execute arbitrary Python code via unspecified vectors.

CVSS2: 6
2%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5492

uid_catalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to obtain metadata about hidden objects via a crafted URL.

CVSS2: 4.3
1%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5491

z3c.form, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain the default form field values by leveraging knowledge of the form location and the element id.

CVSS2: 4.3
1%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5490

Cross-site scripting (XSS) vulnerability in kssdevel.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
1%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5489

The App.Undo.UndoSupport.get_request_var_or_attr function in Zope before 2.12.21 and 3.13.x before 2.13.11, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote authenticated users to gain access to restricted attributes via unspecified vectors.

CVSS2: 3.6
2%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5488

python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to createObject.

CVSS2: 4.6
3%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5487

The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain privileges to bypass the Python sandbox restriction and execute arbitrary Python code via vectors related to importing.

CVSS2: 6
2%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5486

ZPublisher.HTTPRequest._scrubHeader in Zope 2 before 2.13.19, as used in Plone before 4.3 beta 1, allows remote attackers to inject arbitrary HTTP headers via a linefeed (LF) character.

CVSS2: 4.3
3%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5485

registerConfiglet.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via unspecified vectors, related to the admin interface.

CVSS2: 6
2%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5484

The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.

CVSS2: 6.8
1%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5478

The AuthorizationInterceptor in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 does not properly restrict access, which allows remote authenticated users to bypass intended role restrictions and perform arbitrary JMX operations via unspecified vectors.

CVSS2: 4.9
2%
Низкий
больше 13 лет назад
redhat логотип
CVE-2012-5390

The standard universe shadow (condor_shadow.std) component in Condor 7.7.3 through 7.7.6, 7.8.0 before 7.8.5, and 7.9.0 does no properly check privileges, which allows remote attackers to gain privileges via a crafted standard universe job.

CVSS2: 6
2%
Низкий
почти 14 лет назад
redhat логотип
CVE-2012-5375

The CRC32C feature in the Btrfs implementation in the Linux kernel before 3.8-rc1 allows local users to cause a denial of service (prevention of file creation) by leveraging the ability to write to a directory important to the victim, and creating a file with a crafted name that is associated with a specific CRC32C hash value.

CVSS2: 4
1%
Низкий
больше 13 лет назад

Уязвимостей на страницу