Vulnerabilities > Plone > Plone CMS > High

DATE CVE VULNERABILITY TITLE RISK
2008-03-20 CVE-2008-1395 Improper Authentication vulnerability in Plone CMS
Plone CMS does not record users' authentication states, and implements the logout feature solely on the client side, which makes it easier for context-dependent attackers to reuse a logged-out session.
network
low complexity
plone CWE-287
7.5
2008-03-20 CVE-2008-1394 Credentials Management vulnerability in Plone CMS
Plone CMS before 3 places a base64 encoded form of the username and password in the __ac cookie for all user accounts, which makes it easier for remote attackers to obtain access by sniffing the network.
network
low complexity
plone CWE-255
7.5