CVE-2009-0662

The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authenticated users to acquire the identity of an arbitrary user via unspecified vectors.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:plone:plonepas:3.5:*:*:*:*:*:*:*
cpe:2.3:a:plone:plonepas:3.4:*:*:*:*:*:*:*
cpe:2.3:a:plone:plonepas:3.0:*:*:*:*:*:*:*
cpe:2.3:a:plone:plonepas:3.1:*:*:*:*:*:*:*
cpe:2.3:a:plone:plonepas:3.3:*:*:*:*:*:*:*
cpe:2.3:a:plone:plonepas:3.2:*:*:*:*:*:*:*
cpe:2.3:a:plone:plone:*:*:*:*:*:*:*:*

Information

Published : 2009-04-23 10:30

Updated : 2017-08-16 18:29


NVD link : CVE-2009-0662

Mitre link : CVE-2009-0662


JSON object : View

CWE
CWE-287

Improper Authentication

Advertisement

dedicated server usa

Products Affected

plone

  • plone
  • plonepas