PYSEC-2007-4
Dashboard / Vulnerabilities / PYSEC-2007-4
Summary:
Details: Plone 2.5 through 2.5.4 and 3.0 through 3.0.2 allows remote attackers to execute arbitrary Python code via network data containing pickled objects for the (1) statusmessages or (2) linkintegrity module, which the module unpickles and executes.
References: http://plone.org/about/security/advisories/cve-2007-5741, http://www.securityfocus.com/bid/26354, http://secunia.com/advisories/27530, http://secunia.com/advisories/27530, http://www.debian.org/security/2007/dsa-1405, http://secunia.com/advisories/27559, http://osvdb.org/42072, http://osvdb.org/42071, http://www.vupen.com/english/advisories/2007/3754, https://exchange.xforce.ibmcloud.com/vulnerabilities/38288, http://www.securityfocus.com/archive/1/483343/100/0/threaded, https://github.com/advisories/GHSA-hf26-vvmx-x8c8
Affected packages
Package
Name: plone
Purl: pkg:pypi/plone
Affected ranges
Type: ECOSYSTEM
Events:
