Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
plone plone cms 2.1.3 vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2008-1394
Plone CMS prior to 3 places a base64 encoded form of the username and password in the __ac cookie for all user accounts, which makes it easier for remote malicious users to obtain access by sniffing the network.
Plone Plone Cms 2.5
Plone Plone Cms 2.1.2
Plone Plone Cms 2.1.3
Plone Plone Cms
Plone Plone Cms 2.0.5
5.8
CVSSv2
CVE-2013-4200
The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 up to and including 4.1, 4.2.x up to and including 4.2.5, and 4.3.x up to and including 4.3.1 treats URLs starting with a space as a relative URL, which allows remote malicious users to bypass the allow_ex...
Plone Plone 3.3
Plone Plone 4.0.5
Plone Plone 3.0.1
Plone Plone 3.0
Plone Plone 3.2.3
Plone Plone 3.1.4
Plone Plone 3.1.5.1
Plone Plone 2.1.4
Plone Plone 4.0.2
Plone Plone 3.3.5
Plone Plone 3.0.6
Plone Plone 3.2
Plone Plone 3.1.1
Plone Plone 2.1.1
Plone Plone 3.3.4
Plone Plone 3.3.2
Plone Plone 4.0.4
Plone Plone 3.1.7
Plone Plone 4.1
Plone Plone 3.2.2
Plone Plone 2.1.2
Plone Plone 3.0.3
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23316
SQL injection
type confusion
CVE-2024-20697
CVE-2024-4344
local
CVE-2024-30043
CVE-2024-3821
CVE-2024-5041
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started