CVE-2011-0720
Plone 2.5-4.0 - Remote Privilege Escalation and Arbitrary Content Manipulation
Title source: llmDescription
Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products, allows remote attackers to obtain administrative access, read or create arbitrary content, and change the site skin via unknown vectors.
References (10)
Core 10
Core References
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2011-0393.html
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0796
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/70753
Vendor Advisory x_refsource_confirm
http://plone.org/products/plone/security/advisories/cve-2011-0720
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/46102
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/43146
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/65099
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/43914
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1025258
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2011-0394.html
Scores
EPSS
0.0317
EPSS Percentile
86.7%
Details
Status
published
Products (35)
plone/plone
2.5
plone/plone
2.5.1
plone/plone
2.5.2
plone/plone
2.5.3
plone/plone
2.5.4
plone/plone
2.5.5
plone/plone
3.0
plone/plone
3.0.1
plone/plone
3.0.2
plone/plone
3.0.3
... and 25 more
Published
Feb 03, 2011
Tracked Since
Feb 18, 2026