Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-593c-j348-f3gv

Опубликовано: 01 мая 2022
Источник: github
Github: Прошло ревью

Описание

Plone Improper Session Management

Plone CMS before 3, places a base64 encoded form of the username and password in the __ac cookie for the admin account, which makes it easier for remote attackers to obtain administrative privileges by sniffing the network.

Пакеты

Наименование

Plone

pip
Затронутые версииВерсия исправления

< 3.0

3.0

EPSS

Процентиль: 82%
0.0167
Низкий

Связанные уязвимости

ubuntu
больше 17 лет назад

Plone CMS 3.0.5, and probably other 3.x versions, places a base64 encoded form of the username and password in the __ac cookie for the admin account, which makes it easier for remote attackers to obtain administrative privileges by sniffing the network.

nvd
больше 17 лет назад

Plone CMS 3.0.5, and probably other 3.x versions, places a base64 encoded form of the username and password in the __ac cookie for the admin account, which makes it easier for remote attackers to obtain administrative privileges by sniffing the network.

debian
больше 17 лет назад

Plone CMS 3.0.5, and probably other 3.x versions, places a base64 enco ...

EPSS

Процентиль: 82%
0.0167
Низкий