Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
plone plone cms 3.0.5 vulnerabilities and exploits
(subscribe to this query)
10
CVSSv2
CVE-2008-1393
Plone CMS 3.0.5, and probably other 3.x versions, places a base64 encoded form of the username and password in the __ac cookie for the admin account, which makes it easier for remote malicious users to obtain administrative privileges by sniffing the network.
Plone Plone Cms
5.8
CVSSv2
CVE-2013-4200
The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 up to and including 4.1, 4.2.x up to and including 4.2.5, and 4.3.x up to and including 4.3.1 treats URLs starting with a space as a relative URL, which allows remote malicious users to bypass the allow_ex...
Plone Plone 3.3
Plone Plone 4.0.5
Plone Plone 3.0.1
Plone Plone 3.0
Plone Plone 3.2.3
Plone Plone 3.1.4
Plone Plone 3.1.5.1
Plone Plone 2.1.4
Plone Plone 4.0.2
Plone Plone 3.3.5
Plone Plone 3.0.6
Plone Plone 3.2
Plone Plone 3.1.1
Plone Plone 2.1.1
Plone Plone 3.3.4
Plone Plone 3.3.2
Plone Plone 4.0.4
Plone Plone 3.1.7
Plone Plone 4.1
Plone Plone 3.2.2
Plone Plone 2.1.2
Plone Plone 3.0.3
1 EDB exploit
4.3
CVSSv2
CVE-2008-0164
Multiple cross-site request forgery (CSRF) vulnerabilities in Plone CMS 3.0.5 and 3.0.6 allow remote malicious users to (1) add arbitrary accounts via the join_form page and (2) change the privileges of arbitrary groups via the prefs_groups_overview page.
Plone Plone Cms 3.0.5
Plone Plone Cms 3.0.6
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started