5
CVSSv2

CVE-2006-1711

Published: 11/04/2006 Updated: 20/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Plone 2.0.5, 2.1.2, and 2.5-beta1 does not restrict access to the (1) changeMemberPortrait, (2) deletePersonalPortrait, and (3) testCurrentPassword methods, which allows remote malicious users to modify portraits.

Vulnerable Product Search on Vulmon Subscribe to Product

plone plone 2.0.5

plone plone 2.1.2

plone plone 2.5_beta1

Vendor Advisories

It was discovered that the Plone content management system lacks security declarations for three internal classes This allows manipulation of user portraits by unprivileged users The old stable distribution (woody) doesn't contain Plone For the stable distribution (sarge) this problem has been fixed in version 204-3sarge1 For the unstable dis ...

Exploits

source: wwwsecurityfocuscom/bid/17484/info Plone is susceptible to a remote access-control bypass vulnerability This issue is due to the application's failure to properly enforce privileges to various MembershipTool methods This issue allows remote, anonymous attackers to modify and delete portrait images of members This may help atta ...