CVE-2007-5741
Summary
| CVE | CVE-2007-5741 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-11-07 21:46:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Plone 2.5 through 2.5.4 and 3.0 through 3.0.2 allows remote attackers to execute arbitrary Python code via network data containing pickled objects for the (1) statusmessages or (2) linkintegrity module, which the module unpickles and executes. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Plone | Plone | 2.5 | All | All | All |
| Application | Plone | Plone | 2.5.1 | All | All | All |
| Application | Plone | Plone | 2.5.1_rc | All | All | All |
| Application | Plone | Plone | 2.5.4 | All | All | All |
| Application | Plone | Plone | 2.5_beta1 | All | All | All |
| Application | Plone | Plone | 3.0 | All | All | All |
| Application | Plone | Plone | 3.0.1 | All | All | All |
| Application | Plone | Plone | 3.0.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| osvdb.org/42072 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| osvdb.org/42071 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Plone Multiple Modules Script Execution Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| CVE-2007-5741: Unsafe data interpreted as pickles — Plone CMS: Open Source Content Management | af854a3a-2127-422b-91ae-364da2661108 | plone.org | |
| Debian -- Security Information -- DSA-1405-3 zope-cmfplone | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Debian update for zope-cmfplone - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Plone "statusmessages" and "linkintegrity" Modules Code Execution - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| Webmail | OVH- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2007-11-08 | Mark J Cox | Not vulnerable. This issue did not affect versions of plone included in conga/luci packages as shipped with Red Hat Enterprise Linux 5 or Red Hat Cluster Suite for Red Hat Enterprise Linux 4. |
Legacy QID Mappings
- 995373 Python (Pip) Security Update for plone (GHSA-hf26-vvmx-x8c8)