CVE-2008-1393: Critical severity plone cms vulnerability
Plone CMS 3.0.5, and probably other 3.x versions, places a base64 encoded form of the username and password in the ac cookie for the admin account, which makes it easier for remote attackers to obtain administrative privileges by sniffing the network.
Other sources
Plone CMS before 3, places a base64 encoded form of the username and password in the ac cookie for the admin account, which makes it easier for remote attackers to obtain administrative privileges by sniffing the network.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1393?
CVE-2008-1393 is considered a high severity vulnerability due to the ease with which attackers can gain administrative privileges.
How do I fix CVE-2008-1393?
To fix CVE-2008-1393, upgrade Plone CMS to version 3.0.6 or later, which addresses the insecure handling of admin credentials.
What are the risks associated with CVE-2008-1393?
The risks include unauthorized access to the Plone CMS admin interface, leading to potential data breaches and site compromise.
Which versions of Plone are affected by CVE-2008-1393?
CVE-2008-1393 affects Plone CMS versions prior to 3.0.6, specifically 3.0.5 and earlier versions.
How does CVE-2008-1393 impact user security?
CVE-2008-1393 compromises user security by exposing admin credentials in a way that can be intercepted, allowing attackers to gain unauthorized access.