Plone CMS before 3 places a base64 encoded form of the username and password in the __ac cookie for all user accounts, which makes it easier for remote attackers to obtain access by sniffing the network.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Plone_cms | Plone | * | 2.5.1 (including) |
Plone_cms | Plone | 2.0.5 (including) | 2.0.5 (including) |
Plone_cms | Plone | 2.1.2 (including) | 2.1.2 (including) |
Plone_cms | Plone | 2.1.3-rc1 (including) | 2.1.3-rc1 (including) |
Plone_cms | Plone | 2.5 (including) | 2.5 (including) |
Plone_cms | Plone | 2.5-beta1 (including) | 2.5-beta1 (including) |
Plone_cms | Plone | 2.5-beta2 (including) | 2.5-beta2 (including) |
Zope-cmfplone | Ubuntu | dapper | * |
Zope-cmfplone | Ubuntu | edgy | * |
Zope-cmfplone | Ubuntu | feisty | * |
Zope-cmfplone | Ubuntu | gutsy | * |
Zope-cmfplone | Ubuntu | hardy | * |
Zope-cmfplone | Ubuntu | intrepid | * |