FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2011-0720

This CVE name corresponds to:

Entered Topic
2011-02-10 plone -- Remote Security Bypass

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2011-0720
Phase Assigned(20110131)

Description

Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products, allows remote attackers to obtain administrative access, read or create arbitrary content, and change the site skin via unknown vectors.

References

Source Reference
CONFIRM http://plone.org/products/plone/security/advisories/cve-2011-0720
REDHAT RHSA-2011:0393
REDHAT RHSA-2011:0394
BID 46102
OSVDB 70753
SECTRACK 1025258
SECUNIA 43146
SECUNIA 43914
VUPEN ADV-2011-0796
XF plone-unspec-priv-escalation(65099)