CVE-2011-3587High▾ MidnightPoC availableZope Command Execution Vulnerability
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.3 · likelihood 15.6 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
79%
Exploit-DB · Metasploit ×1 (last check)
Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to execute arbitrary commands via vectors related to the p_ class in OFS/misc_.py and the use of Python modules.
zope2 >= 2.12.0, < 2.12.20zope2 >= 2.13.0, < 2.13.10Upgrade to a patched release:
zope2 2.12.20zope2 2.13.10Connected by shared product, vendor, weakness, or advisory.