Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Sébastien Delafond

Researcher fromDebian
#39059of 56,335
7.5Total CVSS
Vulnerabilities · 1
PT-2010-4425
7.5
2010-08-20
Zope · Zope-Ldapuserfolder · CVE-2010-2944
**Name of the Vulnerable Software and Affected Versions** zope-ldapuserfolder version 2.9-1 **Description** The issue concerns the authenticate function in LDAPUserFolder/LDAPUserFolder.py, which fails to verify the password for the emergency account. This allows remote attackers to gain privileges. **Recommendations** For zope-ldapuserfolder version 2.9-1, consider disabling the emergency account or restricting its access until a patch is available to verify the password correctly.