MEDIUM
Plone 2.0.5, 2.1.2, and 2.5-beta1 does not restrict access to the (1) changeMemberPortrait, (2) deletePersonalPortrait, and (3) testCurrentPassword methods, which allows remote attackers to modify portraits
Published Apr 11, 2006
5.0
MEDIUMCVSS 2.0
EPSS 4.02%
Description
Plone 2.0.5, 2.1.2, and 2.5-beta1 does not restrict access to the (1) changeMemberPortrait, (2) deletePersonalPortrait, and (3) testCurrentPassword methods, which allows remote attackers to modify portraits.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (13)
- http://dev.plone.org/plone/ticket/5432 x_refsource_MISC
- http://secunia.com/advisories/19633 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/19640 third-party-advisoryx_refsource_SECUNIA
- http://www.debian.org/security/2006/dsa-1032 vendor-advisoryx_refsource_DEBIAN
- http://www.securityfocus.com/bid/17484 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2006/1340 vdb-entryx_refsource_VUPEN
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4335 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25781 vdb-entryx_refsource_XF
- https://github.com/advisories/GHSA-jcwh-rj6j-vm75 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2006-1711
- https://svn.plone.org/svn/plone/PloneHotfix20060410/trunk/README.txt x_refsource_CONFIRM
- https://web.archive.org/web/20060412111111/https://dev.plone.org/plone/ticket/5432
- https://web.archive.org/web/20060422195724/http://www.securityfocus.com/bid/17484
| Link | Providers | Tags |
|---|---|---|
| http://dev.plone.org/plone/ticket/5432 | x_refsource_MISC | |
| http://secunia.com/advisories/19633 | third-party-advisoryx_refsource_SECUNIA | |
| http://secunia.com/advisories/19640 | third-party-advisoryx_refsource_SECUNIA | |
| http://www.debian.org/security/2006/dsa-1032 | vendor-advisoryx_refsource_DEBIAN | |
| http://www.securityfocus.com/bid/17484 | vdb-entryx_refsource_BID | |
| http://www.vupen.com/english/advisories/2006/1340 | vdb-entryx_refsource_VUPEN | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4335 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/25781 | vdb-entryx_refsource_XF | |
| https://github.com/advisories/GHSA-jcwh-rj6j-vm75 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2006-1711 | ||
| https://svn.plone.org/svn/plone/PloneHotfix20060410/trunk/README.txt | x_refsource_CONFIRM | |
| https://web.archive.org/web/20060412111111/https://dev.plone.org/plone/ticket/5432 | ||
| https://web.archive.org/web/20060422195724/http://www.securityfocus.com/bid/17484 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 11, 2006
Updated Aug 7, 2024
Reserved Apr 11, 2006
Link CVE-2006-1711
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-4335 GHSA-JCWH-RJ6J-VM75 Assigner mitre
Published Apr 11, 2006
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2022-4335