Executive brief
python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to createObject.
Affected products
- PyPI plone
Junglewise Threat Intelligence
CVE-2012-5488 · Severity: low · CVSS 3.1 · Published 2014-09-30
Technologies: plone (PyPI). Vendors: PyPI.
python_scripts.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to execute Python code via a crafted URL, related to createObject.