CVE-2006-4249: Medium severity Plone plone vulnerability
Published Dec 7, 2006
·Updated
Unspecified vulnerability in PlonePAS in Plone 2.5 and 2.5.1, when anonymous member registration is enabled, allows an attacker to "masquerade as a group."
Affected Software
3 affected componentsFixes available
pip/Plone>=2.5<=2.5.1
2.5.2
Plone plone=2.5
Plone plone=2.5.1
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 7, 2006
CVE Published
via NVD·11:28 PM
Data Sourced
via NVD·11:28 PM
RemedyDescriptionSeverityAffected Software
Dec 8, 2006
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
May 1, 2022
Advisory Published
via GitHub·07:16 AM
Frequently Asked Questions
1
What is the severity of CVE-2006-4249?
CVE-2006-4249 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2006-4249?
To fix CVE-2006-4249, upgrade Plone to version 2.5.2 or later.
3
Which versions of Plone are affected by CVE-2006-4249?
CVE-2006-4249 affects Plone versions 2.5 and 2.5.1.
4
What type of attack can be performed due to CVE-2006-4249?
CVE-2006-4249 allows an attacker to masquerade as a group when anonymous member registration is enabled.
5
Is there a known exploit for CVE-2006-4249?
Yes, there are known exploit methods for CVE-2006-4249 that can be used to exploit the vulnerability.