CVE Vulnerabilities

CVE-2001-1227

Published: Oct 10, 2001 | Modified: Oct 10, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.

Affected Software

Name Vendor Start Version End Version
Zope Zope 2.2.0 (including) 2.2.0 (including)
Zope Zope 2.2.1 (including) 2.2.1 (including)
Zope Zope 2.2.2 (including) 2.2.2 (including)
Zope Zope 2.2.3 (including) 2.2.3 (including)
Zope Zope 2.2.4 (including) 2.2.4 (including)
Zope Zope 2.2.5 (including) 2.2.5 (including)

References