Secunia Logo
Netsikker nu! 2008
 
CVE Reference: CVE-2007-5741
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-5741

Description:
Plone 2.5 through 2.5.4 and 3.0 through 3.0.2 allows remote attackers to execute arbitrary Python code via network data containing pickled objects for the (1) statusmessages or (2) linkintegrity module, which the module unpickles and executes.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/38288

SAID
  Secunia Advisory: SA27530
  Secunia Advisory: SA27559

DEBIAN
  http://www.debian.org/security/2007/dsa-1405

CONFIRM
  http://plone.org/about/security/advisories/cve-2007-5741

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/483343/100/0/threaded

BID
  26354


Return to the previous page.