CVE-2006-1711

Plone <2.5 - Info Disclosure

Title source: llm

Description

Plone 2.0.5, 2.1.2, and 2.5-beta1 does not restrict access to the (1) changeMemberPortrait, (2) deletePersonalPortrait, and (3) testCurrentPassword methods, which allows remote attackers to modify portraits.

Exploits (1)

exploitdb WORKING POC VERIFIED
by MJ0011 · textremotelinux
https://www.exploit-db.com/exploits/27630

Scores

EPSS 0.1172
EPSS Percentile 93.7%

Details

Status published
Products (4)
plone/plone 2.0.5
plone/plone 2.1.2
plone/plone 2.5_beta1
pypi/plone 0 - 2.0.6PyPI
Published Apr 11, 2006
Tracked Since Feb 18, 2026