Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.58739
Category:Debian Local Security Checks
Title:Debian Security Advisory DSA 1405-2 (zope-cmfplone)
Summary:The remote host is missing an update to zope-cmfplone announced via advisory DSA 1405-2.;; This VT has been deprecated and merged into the VT 'Debian: Security Advisory (DSA-1405)' (OID: 1.3.6.1.4.1.25623.1.0.60071).
Description:Summary:
The remote host is missing an update to zope-cmfplone announced via advisory DSA 1405-2.

This VT has been deprecated and merged into the VT 'Debian: Security Advisory (DSA-1405)' (OID: 1.3.6.1.4.1.25623.1.0.60071).

Vulnerability Insight:
The zope-cmfplone update in DSA 1405 introduced a regression. This update
corrects this flaw. For completeness, the original advisory text below:

It was discovered that Plone, a web content management system, allows
remote attackers to execute arbitrary code via specially crafted web
browser cookies.

The oldstable distribution (sarge) is not affected by this problem.

For the stable distribution (etch) this problem has been fixed in
version 2.5.1-4etch2.

For the unstable distribution (sid) this problem will be fixed soon.

Solution:
We recommend that you upgrade your zope-cmfplone package.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2007-5741
BugTraq ID: 26354
http://www.securityfocus.com/bid/26354
Bugtraq: 20071106 [CVE-2007-5741] Plone: statusmessages and linkintegrity unsafe network data hotfix (Google Search)
http://www.securityfocus.com/archive/1/483343/100/0/threaded
Debian Security Information: DSA-1405 (Google Search)
http://www.debian.org/security/2007/dsa-1405
http://osvdb.org/42071
http://osvdb.org/42072
http://secunia.com/advisories/27530
http://secunia.com/advisories/27559
http://www.vupen.com/english/advisories/2007/3754
XForce ISS Database: plone-pythoncode-execution(38288)
https://exchange.xforce.ibmcloud.com/vulnerabilities/38288
CopyrightCopyright (C) 2008 E-Soft Inc.

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.