4.3
CVSSv2

CVE-2008-1396

Published: 20/03/2008 Updated: 11/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Plone CMS 3.x uses invariant data (a client username and a server secret) when calculating an HMAC-SHA1 value for an authentication cookie, which makes it easier for remote malicious users to gain permanent access to an account by sniffing the network.

Vulnerable Product Search on Vulmon Subscribe to Product

plone plone cms