CVE-2008-1394
HIGH
7.5
CVSS Severity Score
Vulnerability Description
Plone CMS before 3 places a base64 encoded form of the username and password in the __ac cookie for all user accounts, which makes it easier for remote attackers to obtain access by sniffing the network.
Affected Platforms (CPE)
π¦
Plone
Plone Cms
<= 2.5.1π¦
Plone
Plone Cms
= 2.0.5π¦
Plone
Plone Cms
= 2.1.2π¦
Plone
Plone Cms
= 2.1.3π¦
Plone
Plone Cms
= 2.5π¦
Plone
Plone Cms
= 2.5π¦
Plone
