CVE-2008-1394
HIGH
7.5
CVSS Severity Score
Vulnerability Description
Plone CMS before 3 places a base64 encoded form of the username and password in the __ac cookie for all user accounts, which makes it easier for remote attackers to obtain access by sniffing the network.
Affected Platforms (CPE)
📦
Plone
Plone Cms
<= 2.5.1📦
Plone
Plone Cms
= 2.0.5📦
Plone
Plone Cms
= 2.1.2📦
Plone
Plone Cms
= 2.1.3📦
Plone
Plone Cms
= 2.5📦
Plone
Plone Cms
= 2.5📦
Plone
