CVE-2006-4247
Published Sep 29, 2006
Last updated 16 years ago
Overview
- Description
- Unspecified vulnerability in the Password Reset Tool before 0.4.1 on Plone 2.5 and 2.5.1 Release Candidate allows attackers to reset the passwords of other users, related to "an erroneous security declaration."
- Source
- security@debian.org
- NVD status
- Analyzed
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.4
- Impact score
- 4.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:N
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:plone:plone:2.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9762C674-380B-4831-BBA1-3B27742121B0" }, { "criteria": "cpe:2.3:a:plone:plone:2.5.1_rc:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C01E0884-D0A4-4511-AD4B-DBB09CB8080E" } ], "operator": "OR" } ] } ]