Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Plone CMS 3.0.5, and probably other 3.x versions, places a base64 encoded form of the username and password in the __ac cookie for the admin account, which makes it easier for remote attackers to obtain administrative privileges by sniffing the network.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Plone CMS 管理账户__ac cookie安全特权漏洞
Vulnerability Description
Plone CMS 3.0.5, 及其他可能的3.x版本,放置了一个base64编码的用户名和密码形式在管理账户的__ac cookie中,远程攻击者通过嗅探网络来取得管理特权变得简单。
CVSS Information
N/A
Vulnerability Type
N/A