CVE-2006-1711
Plone <2.5 - Info Disclosure
Title source: llmDescription
Plone 2.0.5, 2.1.2, and 2.5-beta1 does not restrict access to the (1) changeMemberPortrait, (2) deletePersonalPortrait, and (3) testCurrentPassword methods, which allows remote attackers to modify portraits.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by MJ0011 · textremotelinux
https://www.exploit-db.com/exploits/27630
References (8)
Scores
EPSS
0.1172
EPSS Percentile
93.7%
Details
Status
published
Products (4)
plone/plone
2.0.5
plone/plone
2.1.2
plone/plone
2.5_beta1
pypi/plone
0 - 2.0.6PyPI
Published
Apr 11, 2006
Tracked Since
Feb 18, 2026