7.5

CVE-2008-1394

Plone CMS before 3 places a base64 encoded form of the username and password in the __ac cookie for all user accounts, which makes it easier for remote attackers to obtain access by sniffing the network.

Data is provided by the National Vulnerability Database (NVD)
PlonePlone Cms Version <= 2.5.1
PlonePlone Cms Version2.0.5
PlonePlone Cms Version2.1.2
PlonePlone Cms Version2.1.3 Updaterc1
PlonePlone Cms Version2.5
PlonePlone Cms Version2.5 Updatebeta1
PlonePlone Cms Version2.5 Updatebeta2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.72% 0.715
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P