CVE Vulnerabilities

CVE-2000-1212

Published: Dec 18, 2000 | Modified: Nov 20, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects.

Affected Software

Name Vendor Start Version End Version
Zope Zope 2.2.0 (including) 2.2.0 (including)
Zope Zope 2.2.0a1 (including) 2.2.0a1 (including)
Zope Zope 2.2.0b1 (including) 2.2.0b1 (including)
Zope Zope 2.2.0b2 (including) 2.2.0b2 (including)
Zope Zope 2.2.0b3 (including) 2.2.0b3 (including)
Zope Zope 2.2.0b4 (including) 2.2.0b4 (including)
Zope Zope 2.2.1 (including) 2.2.1 (including)
Zope Zope 2.2.1b1 (including) 2.2.1b1 (including)
Zope Zope 2.2.2 (including) 2.2.2 (including)
Zope Zope 2.2.3 (including) 2.2.3 (including)
Zope Zope 2.2.4 (including) 2.2.4 (including)
Red Hat Powertools 6.2 RedHat *
Red Hat Powertools 7.0 RedHat *

References