CVE-2008-1394
Published Mar 20, 2008
Last updated 6 years ago
Overview
- Description
- Plone CMS before 3 places a base64 encoded form of the username and password in the __ac cookie for all user accounts, which makes it easier for remote attackers to obtain access by sniffing the network.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-255
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:plone:plone_cms:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C4A55D03-9FDD-466B-BA65-42996B4F802C", "versionEndIncluding": "2.5.1" }, { "criteria": "cpe:2.3:a:plone:plone_cms:2.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "079F5BAC-8873-4087-9030-3036E84B06FC" }, { "criteria": "cpe:2.3:a:plone:plone_cms:2.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DA64F59B-A021-4EE5-8CCD-BB7FA0FB5B51" }, { "criteria": "cpe:2.3:a:plone:plone_cms:2.1.3:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "64130585-46A0-4F0D-9DD1-8E42AF2CE054" }, { "criteria": "cpe:2.3:a:plone:plone_cms:2.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "09B101F0-679D-4346-B35E-113E27C952B4" }, { "criteria": "cpe:2.3:a:plone:plone_cms:2.5:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "489E848B-DB59-4FCB-85B8-7338547013AB" }, { "criteria": "cpe:2.3:a:plone:plone_cms:2.5:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BABF434A-91C0-490B-BD2A-FBE83F8AA954" } ], "operator": "OR" } ] } ]