CVE-2012-5488

EUVD-2014-0048
python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to createObject.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 70%
Affected Products (NVD)
VendorProductVersion
ploneplone
𝑥
≤ 4.2.2
ploneplone
1.0
ploneplone
1.0.1
ploneplone
1.0.2
ploneplone
1.0.3
ploneplone
1.0.4
ploneplone
1.0.5
ploneplone
1.0.6
ploneplone
2.0
ploneplone
2.0.1
ploneplone
2.0.2
ploneplone
2.0.3
ploneplone
2.0.4
ploneplone
2.0.5
ploneplone
2.1
ploneplone
2.1.1
ploneplone
2.1.2
ploneplone
2.1.3
ploneplone
2.1.4
ploneplone
2.5
ploneplone
2.5.1
ploneplone
2.5.2
ploneplone
2.5.3
ploneplone
2.5.4
ploneplone
2.5.5
ploneplone
3.0
ploneplone
3.0.1
ploneplone
3.0.2
ploneplone
3.0.3
ploneplone
3.0.4
ploneplone
3.0.5
ploneplone
3.0.6
ploneplone
3.1
ploneplone
3.1.1
ploneplone
3.1.2
ploneplone
3.1.3
ploneplone
3.1.4
ploneplone
3.1.5.1
ploneplone
3.1.6
ploneplone
3.1.7
ploneplone
3.2
ploneplone
3.2.1
ploneplone
3.2.2
ploneplone
3.2.3
ploneplone
3.3
ploneplone
3.3.1
ploneplone
3.3.2
ploneplone
3.3.3
ploneplone
3.3.4
ploneplone
3.3.5
ploneplone
4.0
ploneplone
4.0.1
ploneplone
4.0.2
ploneplone
4.0.3
ploneplone
4.0.4
ploneplone
4.0.5
ploneplone
4.0.6.1
ploneplone
4.1
ploneplone
4.1.4
ploneplone
4.1.5
ploneplone
4.1.6
ploneplone
4.2
ploneplone
4.2:a1
ploneplone
4.2:a2
ploneplone
4.2:b1
ploneplone
4.2:b2
ploneplone
4.2:rc1
ploneplone
4.2:rc2
ploneplone
4.2.0.1
ploneplone
4.2.1
ploneplone
4.2.1.1
ploneplone
4.3
𝑥
= Vulnerable software versions