Plone < 3.0.0 Multiple Vulnerabilities

critical Nessus Plugin ID 328998

Synopsis

The remote host is affected by multiple vulnerabilities.

Description

The version of Plone installed on the remote host is prior to 3.0.0. It is, therefore, affected by the following vulnerabilities:

- Plone places a base64 encoded form of the username and password in the __ac cookie for the admin account, which makes it easier for remote attackers to obtain administrative privileges by sniffing the network.
(CVE-2008-1393)

- Plone CMS before 3 places a base64 encoded form of the username and password in the __ac cookie for all user accounts, which makes it easier for remote attackers to obtain access by sniffing the network.
(CVE-2008-1394)

- Plone CMS does not record users' authentication states, and implements the logout feature solely on the client side, which makes it easier for context-dependent attackers to reuse a logged-out session.
(CVE-2008-1395)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Plone version 3.0.0 or later.

See Also

https://cxsecurity.com/issue/WLB-2008030047

https://exchange.xforce.ibmcloud.com/vulnerabilities/41423

https://exchange.xforce.ibmcloud.com/vulnerabilities/41425

https://exchange.xforce.ibmcloud.com/vulnerabilities/41427

https://github.com/advisories/GHSA-593c-j348-f3gv

https://github.com/advisories/GHSA-mq3q-jjph-rp5p

https://github.com/advisories/GHSA-wm2x-72w2-c6gx

Plugin Details

Severity: Critical

ID: 328998

File Name: plone_3_0_0.nasl

Version: 1.2

Type: Local

Family: Misc.

Published: 7/22/2026

Updated: 7/23/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.12

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2008-1393

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:plone:plone

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 3/19/2008

Vulnerability Publication Date: 3/19/2008

Reference Information

CVE: CVE-2008-1393, CVE-2008-1394, CVE-2008-1395