CVE Vulnerabilities

CVE-2000-1212

Published: Dec 18, 2000 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects.

Affected Software

NameVendorStart VersionEnd Version
ZopeZope2.2.0 (including)2.2.0 (including)
ZopeZope2.2.0a1 (including)2.2.0a1 (including)
ZopeZope2.2.0b1 (including)2.2.0b1 (including)
ZopeZope2.2.0b2 (including)2.2.0b2 (including)
ZopeZope2.2.0b3 (including)2.2.0b3 (including)
ZopeZope2.2.0b4 (including)2.2.0b4 (including)
ZopeZope2.2.1 (including)2.2.1 (including)
ZopeZope2.2.1b1 (including)2.2.1b1 (including)
ZopeZope2.2.2 (including)2.2.2 (including)
ZopeZope2.2.3 (including)2.2.3 (including)
ZopeZope2.2.4 (including)2.2.4 (including)
Red Hat Powertools 6.2RedHat*
Red Hat Powertools 7.0RedHat*

References