Release date:
Updated on:
Affected Systems:
Plone 3.3-4.3.2
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2013-7060
Plone is an open-source CMS system.
In Plone 3.3-4.3.2, Products, CMFPlone, and FactoryTool. py have a security vulnerability, which allows remote administrators to exploit this vulnerability to obtain installation path information.
<* Source: Richard Mitchell
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Plone
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://plone.org/products/plone/security/
Https://plone.org/security/20131210/catalogue-exposure
Http://www.openwall.com/lists/oss-security/2013/12/12/3
Http://www.openwall.com/lists/oss-security/2013/12/10/15
This article permanently updates the link address: