Sploitus

CVE-2011-4462

1 known exploit for CVE-2011-4462

Plone 4.1.3 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

Affected products
Plone
Plone
≤ 4.1.3, 1.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 2.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.1, 2.1.1, 2.1.2, 2.1.3, 2.1.4, 2.5, 2.5.1, 2.5.2, 2.5.3, 2.5.4, 2.5.5, 3.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.1, 3.1.1, 3.1.2, 3.1.3, 3.1.4, 3.1.5.1, 3.1.6, 3.1.7
CVSS 2.0
5.0 MEDIUM
EPSS
3.3% (87th percentile)
Weakness
CWE-20
NVD status
Modified
Published
2011-12-30
CVE-2011-4462 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2011-4462

Proof-of-concept code and exploit modules indexed by Sploitus