Back to search
CVE-2007-5741
Published: Nov 7, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
Plone 2.5 through 2.5.4 and 3.0 through 3.0.2 allows remote attackers to execute arbitrary Python code via network data containing pickled objects for the (1) statusmessages or (2) linkintegrity module, which the module unpickles and executes.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
plone-pythoncode-execution(38288)
vdb-entry
x_refsource_XF
42071
vdb-entry
x_refsource_OSVDB
26354
vdb-entry
x_refsource_BID
27559
third-party-advisory
x_refsource_SECUNIA
27530
third-party-advisory
x_refsource_SECUNIA
20071106 [CVE-2007-5741] Plone: statusmessages and linkintegrity unsafe network data hotfix
mailing-list
x_refsource_BUGTRAQ
DSA-1405
vendor-advisory
x_refsource_DEBIAN
ADV-2007-3754
vdb-entry
x_refsource_VUPEN
http://plone.org/about/security/advisories/cve-2007-5741
x_refsource_CONFIRM
42072
vdb-entry
x_refsource_OSVDB
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now