CVE-2010-2944

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
20/08/2010
Last modified:
11/04/2025

Description

The authenticate function in LDAPUserFolder/LDAPUserFolder.py in zope-ldapuserfolder 2.9-1 does not verify the password for the emergency account, which allows remote attackers to gain privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jens_vagelpohl:zope-ldapuserfolder:2.9-1:*:*:*:*:*:*:*