Description
A vulnerability exists in Zope 2.12.x and Zope 2.13.x allows execution of arbitrary code by anonymous users. This is a severe vulnerability that allows an unauthenticated attacker to employ a carefully crafted web request to execute arbitrary commands with the privileges of the Zope/Plone service.
Versions Affected: Plone 4.0 (through 4.0.9); Plone 4.1; Plone 4.2 (a1 and a2); Zope 2.12.x and Zope 2.13.x.
Versions Not Affected: Versions of Plone that use Zope other than Zope 2.12.x and Zope 2.13.x.
Remediation
Apply the Plone Hotfix 20110928 (Oct 04, 2011).
References
Security vulnerability announcement: 20110928 - Arbitrary Code Execution
Related Vulnerabilities
WordPress 2.0.6 'Zend_Hash_Del_Key_Or_Index' SQL Injection Vulnerability (0.6.2 - 2.0.6)
PHP Other Vulnerability (CVE-2007-1890)
WordPress Plugin My Tickets Security Bypass (1.9.11)
WordPress Plugin Fitness Trainer-Training Membership Cross-Site Scripting (1.0.8)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-7849)