Executive Summary
Summary | |
---|---|
Title | New zope-cmfplone packages fix unprivileged data manipulation |
Informations | |||
---|---|---|---|
Name | DSA-1032 | First vendor Publication | 2006-04-12 |
Vendor | Debian | Last vendor Modification | 2006-04-12 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:N/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
It was discovered that the Plone content management system lacks security declarations for three internal classes. This allows manipulation of user portraits by unprivileged users. The old stable distribution (woody) doesn't contain Plone. For the stable distribution (sarge) this problem has been fixed in version 2.0.4-3sarge1. For the unstable distribution (sid) this problem has been fixed in version 2.1.2-2. We recommend that you upgrade your zope-cmfplone package. |
Original Source
Url : http://www.debian.org/security/2006/dsa-1032 |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 3 |
OpenVAS Exploits
Date | Description |
---|---|
2008-09-04 | Name : FreeBSD Ports: plone File : nvt/freebsd_plone.nasl |
2008-09-04 | Name : FreeBSD Ports: plone File : nvt/freebsd_plone0.nasl |
2008-01-17 | Name : Debian Security Advisory DSA 1032-1 (zope-cmfplone) File : nvt/deb_1032_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
24582 | Plone Multiple Method member_id Parameter Portrait Manipulation |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2006-10-20 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_b6c189565fa311dbad2d0016179b2dd5.nasl - Type : ACT_GATHER_INFO |
2006-10-14 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1032.nasl - Type : ACT_GATHER_INFO |
2006-05-13 | Name : The remote FreeBSD host is missing a security-related update. File : freebsd_pkg_22c6b826cee011da857800123ffe8333.nasl - Type : ACT_GATHER_INFO |
2006-04-14 | Name : The remote web server contains a Python application that is affected by an ac... File : plone_membershiptool_access_control_bypass.nasl - Type : ACT_DESTRUCTIVE_ATTACK |
Alert History
Date | Informations |
---|---|
2014-02-17 11:25:39 |
|