Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Plone CMS 3.x uses invariant data (a client username and a server secret) when calculating an HMAC-SHA1 value for an authentication cookie, which makes it easier for remote attackers to gain permanent access to an account by sniffing the network.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
plone_cms cookie中HMAC-SHA1值嗅探攻击漏洞
Vulnerability Description
Plone CMS 3.x在计算权限cookie中的一个HMAC-SHA1值时,运用不变的数据(一个客户端用户名何一个服务器秘密(secret)),远程攻击者通过嗅探网络来取得永久访问权变得简单。
CVSS Information
N/A
Vulnerability Type
N/A