Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-0662

Опубликовано: 23 апр. 2009
Источник: nvd
CVSS2: 6
EPSS Низкий

Описание

The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authenticated users to acquire the identity of an arbitrary user via unspecified vectors.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:plone:plonepas:3.0:*:*:*:*:*:*:*
cpe:2.3:a:plone:plonepas:3.1:*:*:*:*:*:*:*
cpe:2.3:a:plone:plonepas:3.2:*:*:*:*:*:*:*
cpe:2.3:a:plone:plonepas:3.3:*:*:*:*:*:*:*
cpe:2.3:a:plone:plonepas:3.4:*:*:*:*:*:*:*
cpe:2.3:a:plone:plonepas:3.5:*:*:*:*:*:*:*
cpe:2.3:a:plone:plone:*:*:*:*:*:*:*:*

EPSS

Процентиль: 64%
0.00464
Низкий

6 Medium

CVSS2

Дефекты

CWE-287

Связанные уязвимости

ubuntu
больше 16 лет назад

The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authenticated users to acquire the identity of an arbitrary user via unspecified vectors.

redhat
больше 16 лет назад

The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authenticated users to acquire the identity of an arbitrary user via unspecified vectors.

debian
больше 16 лет назад

The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product ...

github
больше 7 лет назад

Moderate severity vulnerability that affects Products.PlonePAS

EPSS

Процентиль: 64%
0.00464
Низкий

6 Medium

CVSS2

Дефекты

CWE-287