CVE Vulnerabilities

CVE-2000-1211

Published: Dec 16, 2000 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which could allow attackers to perform unauthorized activities.

Affected Software

Name Vendor Start Version End Version
Zope Zope 2.2.0 (including) 2.2.0 (including)
Zope Zope 2.2.0a1 (including) 2.2.0a1 (including)
Zope Zope 2.2.0b1 (including) 2.2.0b1 (including)
Zope Zope 2.2.0b2 (including) 2.2.0b2 (including)
Zope Zope 2.2.0b3 (including) 2.2.0b3 (including)
Zope Zope 2.2.0b4 (including) 2.2.0b4 (including)
Zope Zope 2.2.1 (including) 2.2.1 (including)
Zope Zope 2.2.1b1 (including) 2.2.1b1 (including)
Zope Zope 2.2.2 (including) 2.2.2 (including)
Zope Zope 2.2.3 (including) 2.2.3 (including)
Zope Zope 2.2.4 (including) 2.2.4 (including)

References