CVE-2009-0662
UnknownEPSS 0.96%
Last modified
CVE-2009-0662 is a vulnerability of currently unknown severity. The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authenticated users to acquire the identity of an arbitrary user via unspecified vectors.. EPSS estimates a 0.96% chance of exploitation in the next 30 days.
Description
The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authenticated users to acquire the identity of an arbitrary user via unspecified vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Plone | Plonepas | 3.0 |
| Plone | Plonepas | 3.1 |
| Plone | Plonepas | 3.2 |
| Plone | Plonepas | 3.3 |
| Plone | Plonepas | 3.4 |
| Plone | Plonepas | 3.5 |
References
- http://plone.org/products/plone/security/advisories/cve-2009-0662Patch, Vendor Advisory
- http://secunia.com/advisories/34840Vendor Advisory
- http://plone.org/products/plone/security/advisories/cve-2009-0662Patch, Vendor Advisory
- http://secunia.com/advisories/34840Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-0662?
The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form, which allows remote authenticated users to acquire the identity of an arbitrary user via unspecified vectors.
How severe is CVE-2009-0662?
Severity scoring for CVE-2009-0662 is pending analysis. The EPSS model estimates a 0.96% probability of exploitation in the next 30 days.
How do I fix CVE-2009-0662?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-0656Asus SmartLogon 1.0.0005 allows physically proximate attacke…
- CVE-2009-0657Toshiba Face Recognition 2.0.2.32 allows physically proximat…
- CVE-2009-0658Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat…7.8
- CVE-2009-0659Stack-based buffer overflow in the GetStatsFromLine function…
- CVE-2009-0660Multiple cross-site scripting (XSS) vulnerabilities in Mahar…
- CVE-2009-0661Wee Enhanced Environment for Chat (WeeChat) 0.2.6 allows rem…
- CVE-2009-0663Heap-based buffer overflow in the DBD::Pg (aka DBD-Pg or lib…
- CVE-2009-0664Multiple cross-site scripting (XSS) vulnerabilities in Mahar…
- CVE-2009-0667Untrusted search path vulnerability in Agent/Backend.pm in O…
- CVE-2009-0668Unspecified vulnerability in Zope Object Database (ZODB) bef…
- CVE-2009-0669Zope Object Database (ZODB) before 3.8.2, when certain Zope …
- CVE-2009-0671Rejected reason: Format string vulnerability in the Universi…
Are you affected by CVE-2009-0662?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
