7.5
CVSSv2

CVE-2008-1394

Published: 20/03/2008 Updated: 11/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Plone CMS prior to 3 places a base64 encoded form of the username and password in the __ac cookie for all user accounts, which makes it easier for remote malicious users to obtain access by sniffing the network.

Vulnerable Product Search on Vulmon Subscribe to Product

plone plone cms 2.5

plone plone cms 2.1.2

plone plone cms 2.1.3

plone plone cms

plone plone cms 2.0.5