Plone CMS 3.0.5, and probably other 3.x versions, places a base64 encoded form of the username and password in the __ac cookie for the admin account, which makes it easier for remote attackers to obtain administrative privileges by sniffing the network.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Plone_cms | Plone | * | 3 (including) |
Plone_cms | Plone | * | 3.0.5 (including) |
Zope-cmfplone | Ubuntu | dapper | * |
Zope-cmfplone | Ubuntu | edgy | * |
Zope-cmfplone | Ubuntu | feisty | * |
Zope-cmfplone | Ubuntu | gutsy | * |
Zope-cmfplone | Ubuntu | hardy | * |
Zope-cmfplone | Ubuntu | intrepid | * |