Plone and Zope Multiple Remote Security Vulnerabilities

BID:56341

Info

Plone and Zope Multiple Remote Security Vulnerabilities

Bugtraq ID: 56341
Class: Unknown
CVE: CVE-2012-5485
CVE-2012-5486
CVE-2012-5487
CVE-2012-5488
CVE-2012-5495
CVE-2012-5489
CVE-2012-5490
CVE-2012-5492
CVE-2012-5493
CVE-2012-5494
CVE-2012-5496
CVE-2012-5497
CVE-2012-5498
CVE-2012-5499
CVE-2012-5501
CVE-2012-5502
CVE-2012-5503
CVE-2012-5504
CVE-2012-5505
CVE-2012-5506
CVE-2012-5500
CVE-2012-5507
CVE-2012-5508
Remote: Yes
Local: No
Published: Oct 30 2012 12:00AM
Updated: Mar 19 2015 08:46AM
Credit: WhiteHat security Team, Richard Mitchell and Alan Hoey from Plone security team, John Carr (Isotoma), Daniel Kraft (d9t.de), Alessandro SauZheR, Karl Johan Kleist, , Mauro Gentile, mksht80, Roel Bruggink (fourdigits), David Beitey (James Cook University),
Vulnerable: Zope Zope 3.7.3
Zope Zope 3.4.1
Zope Zope 3.3.3
Zope Zope 3.2.4
Zope Zope 3.1.1
Zope Zope 2.12.22
Zope Zope 2.12.20
Zope Zope 2.12.3
Zope Zope 2.11.7
Zope Zope 2.11.6
Zope Zope 2.11.5
Zope Zope 2.11.4
Zope Zope 2.11.2
Zope Zope 2.10.12
Zope Zope 2.10.11
Zope Zope 2.10.10
Zope Zope 2.10.9
Zope Zope 2.10.7
Zope Zope 2.10.6
Zope Zope 2.10.5
Zope Zope 2.10.4
Zope Zope 2.10.2
Zope Zope 2.10.1
Zope Zope 2.9.12
Zope Zope 2.9.11
Zope Zope 2.9.3
Zope Zope 2.9.2
Zope Zope 2.9.1
Zope Zope 2.9
Zope Zope 2.8.12
Zope Zope 2.8.11
Zope Zope 2.8.8
Zope Zope 2.8.7
Zope Zope 2.8.6
Zope Zope 2.8.5
Zope Zope 2.8.4
Zope Zope 2.8.3
Zope Zope 2.8.2
Zope Zope 2.8.1
Zope Zope 2.7.8
Zope Zope 2.7.7
Zope Zope 2.7.6
Zope Zope 2.7.5
Zope Zope 2.7.4
Zope Zope 2.7.3
Zope Zope 2.7.2
Zope Zope 2.7.1
Zope Zope 2.6.3
Zope Zope 2.6.2
Zope Zope 2.6.1
Zope Zope 2.5.1
Zope Zope 2.4.3
Zope Zope 2.4.2
Zope Zope 2.4.1
Zope Zope 2.3.3
Zope Zope 2.3.2
Zope Zope 2.3.1
Zope Zope 2.2.5
- RedHat Linux 7.1 i386
- RedHat Linux 7.1 alpha
- RedHat Linux 7.0 i386
- RedHat Linux 7.0 alpha
Zope Zope 2.2.4
Zope Zope 2.2.3
Zope Zope 2.2.2
Zope Zope 2.2.1
Zope Zope 2.2
Zope Zope 2.1.7
Zope Zope 2.1.1
Zope Zope 2.13.9
Zope Zope 2.13.8
Zope Zope 2.13.6
Zope Zope 2.13.12
Zope Zope 2.13.10
Zope Zope 2.13
Zope Zope 2.12.19
Zope Zope 2.12
Zope Zope 2.11.8
RedHat Enterprise Linux Clustering 5 server
Plone Plone 4.1.3
Plone Plone 4.0.8
Plone Plone 4.0.7
Plone Plone 3.3.5
Plone Plone 3.3.4
Plone Plone 3.3.3
Plone Plone 3.3.2
Plone Plone 3.3.1
Plone Plone 3.2.3
Plone Plone 3.2.2
Plone Plone 3.1.6
Plone Plone 3.1.4
Plone Plone 3.0.5
Plone Plone 3.0.4
Plone Plone 3.0.3
Plone Plone 3.0.2
Plone Plone 3.0.1
Plone Plone 2.5.5
Plone Plone 2.5.4
Plone Plone 2.5.1
Plone Plone 2.1.2
Plone Plone 2.0.5
Plone Plone 2.0.4
Plone Plone 4.2
Plone Plone 4.1
Plone Plone 4.0.9
Plone Plone 4.0.6.1
Plone Plone 4.0.5
Plone Plone 4.0.4
Plone Plone 4.0.3
Plone Plone 4.0.2
Plone Plone 4.0.1
Plone Plone 4.0
Plone Plone 3.3.2
Plone Plone 3.3.1
Plone Plone 3.3
Plone Plone 3.3
Plone Plone 3.2.3
Plone Plone 3.2.2
Plone Plone 3.2.1
Plone Plone 3.2
Plone Plone 3.1.7
Plone Plone 3.1.6
Plone Plone 3.1.5.1
Plone Plone 3.1.3
Plone Plone 3.1.2
Plone Plone 3.1.1
Plone Plone 3.1
Plone Plone 3.0.6
Plone Plone 3.0
Plone Plone 2.5
Plone Plone 2.1.3
Plone Plone 2.1.1
Plone Plone 2.1
Plone Plone 2.0.2
Plone Plone 2.0.1
Plone Plone 2.0
Plone Plone 1.0.6
Plone Plone 1.0.5
Plone Plone 1.0.4
Plone Plone 1.0.3
Plone Plone 1.0.2
Plone Plone 1.0.1
Plone Plone 1.0
Oracle Enterprise Linux 5
CentOS CentOS 5
Not Vulnerable:

Exploit / POC

Plone and Zope Multiple Remote Security Vulnerabilities

Some of these issues can be exploited through a browser.

References

Plone and Zope Multiple Remote Security Vulnerabilities

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report