Plone Unspecified Remote Command Execution Vulnerability
BID:49991
Info
Plone Unspecified Remote Command Execution Vulnerability
| Bugtraq ID: | 49991 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 06 2011 12:00AM |
| Updated: | Oct 06 2011 12:00AM |
| Credit: | Alan Hoey |
| Vulnerable: |
Plone Plone 4.0.8 Plone Plone 4.0.7 Plone Plone 4.2a2 Plone Plone 4.2a1 Plone Plone 4.1 Plone Plone 4.0.9 Plone Plone 4.0.6.1 Plone Plone 4.0.5 Plone Plone 4.0.4 Plone Plone 4.0.3 Plone Plone 4.0.2 Plone Plone 4.0.1 Plone Plone 4.0 |
| Not Vulnerable: | |
Discussion
Plone Unspecified Remote Command Execution Vulnerability
Plone is prone to a remote command-execution vulnerability because it fails to properly validate user-supplied input.
An attacker can exploit this issue to execute arbitrary commands within the context of the webserver.
Plone versions 4.0 through 4.0.9, 4.1, 4.2a1, and 4.2a2 are vulnerable.
Plone is prone to a remote command-execution vulnerability because it fails to properly validate user-supplied input.
An attacker can exploit this issue to execute arbitrary commands within the context of the webserver.
Plone versions 4.0 through 4.0.9, 4.1, 4.2a1, and 4.2a2 are vulnerable.
Exploit / POC
Plone Unspecified Remote Command Execution Vulnerability
An attacker can exploit this issue through a browser.
An attacker can exploit this issue through a browser.
References
Plone Unspecified Remote Command Execution Vulnerability
References:
References: