CVE Vulnerabilities

CVE-2000-1212

Published: Dec 18, 2000 | Modified: Oct 10, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects.

Affected Software

Name Vendor Start Version End Version
Zope Zope 2.2.0 2.2.0
Zope Zope 2.2.0a1 2.2.0a1
Zope Zope 2.2.0b1 2.2.0b1
Zope Zope 2.2.0b2 2.2.0b2
Zope Zope 2.2.0b3 2.2.0b3
Zope Zope 2.2.0b4 2.2.0b4
Zope Zope 2.2.1 2.2.1
Zope Zope 2.2.1b1 2.2.1b1
Zope Zope 2.2.2 2.2.2
Zope Zope 2.2.3 2.2.3
Zope Zope 2.2.4 2.2.4

References