peter bassill · operator
$ cve CVE-2011-3587 JSON

CVE-2011-3587 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 78.1% (pctl 100)

Patch early

A public exploit exists.

Description

Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to execute arbitrary commands via vectors related to the p_ class in OFS/misc_.py and the use of Python modules.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS78.08% — more likely to be exploited than 100% of all CVEs
On CISA KEVno
Public exploityes
Published2011-10-10
Last modified2026-06-16

Affected (2)

VendorProduct
ploneplone
zopezope

Public exploits

SourceTitleDate
exploit-dbPlone and Zope - Remote Command Execution2011-12-21

References

→ the Explorer  ·  watch your stack  ·  NVD