Vulnerability Name: | CVE-2006-4247 (CCN-32962) | ||||||||
Assigned: | 2006-09-29 | ||||||||
Published: | 2006-09-29 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | Unspecified vulnerability in the Password Reset Tool before 0.4.1 on Plone 2.5 and 2.5.1 Release Candidate allows attackers to reset the passwords of other users, related to "an erroneous security declaration." | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N) 4.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Other | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-4247 Source: CCN Type: Plone Web site plone.org - plone.org Source: CCN Type: Plone Security Advisory Password reset vulnerability (CVE-2006-4247) Source: CONFIRM Type: Patch http://plone.org/about/security/advisories/cve-2006-4247 Source: CCN Type: OSVDB ID: 41855 Plone Password Reset Tool Arbitrary Password Reset Source: XF Type: UNKNOWN plone-passwordresettool-weak-security(32962) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |