at_download.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read arbitrary BLOBs (Files and Images) stored on custom content types via a crafted URL.
Loading...
Loading...
at_download.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read arbitrary BLOBs (Files and Images) stored on custom content types via a crafted URL.
September 30, 2014
May 6, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2012-5501
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.