Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which could allow attackers to perform unauthorized activ…
Info
Summary
Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which could allow attackers to perform unauthorized activities.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- http://www.iss.net/security_center/static/5824.php
- http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-083.php3 Patch
- http://www.osvdb.org/6282
- http://www.redhat.com/support/errata/RHSA-2000-125.html
- http://www.zope.org/Products/Zope/Hotfix_2000-12-08/security_alert Patch
- http://www.iss.net/security_center/static/5824.php
- http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-083.php3 Patch
- http://www.osvdb.org/6282
- http://www.redhat.com/support/errata/RHSA-2000-125.html
- http://www.zope.org/Products/Zope/Hotfix_2000-12-08/security_alert Patch
Timeline
- nvd_ingest NVD