7.5
CVSSv2

CVE-2010-2944

Published: 20/08/2010 Updated: 23/08/2010
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The authenticate function in LDAPUserFolder/LDAPUserFolder.py in zope-ldapuserfolder 2.9-1 does not verify the password for the emergency account, which allows remote malicious users to gain privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

jens vagelpohl zope-ldapuserfolder 2.9-1

Vendor Advisories

Jeremy James discovered that in LDAPUserFolder, a Zope extension used to authenticate against an LDAP server, the authentication code does not verify the password provided for the emergency user Malicious users that manage to get the emergency user login can use this flaw to gain administrative access to the Zope instance, by providing an arbitrar ...