CVE-2011-0720

Plone 2.5-4.0 - Remote Privilege Escalation and Arbitrary Content Manipulation

Title source: llm
STIX 2.1

Description

Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products, allows remote attackers to obtain administrative access, read or create arbitrary content, and change the site skin via unknown vectors.

References (10)

Core 10
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2011-0393.html
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0796
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/70753
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/46102
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43146
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/65099
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43914
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1025258
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2011-0394.html

Scores

EPSS 0.0317
EPSS Percentile 86.7%

Details

Status published
Products (35)
plone/plone 2.5
plone/plone 2.5.1
plone/plone 2.5.2
plone/plone 2.5.3
plone/plone 2.5.4
plone/plone 2.5.5
plone/plone 3.0
plone/plone 3.0.1
plone/plone 3.0.2
plone/plone 3.0.3
... and 25 more
Published Feb 03, 2011
Tracked Since Feb 18, 2026