Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which could allow attackers to perform unauthorized activities.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:34
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.iss.net/security_center/static/5824.php - | |
References | () http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-083.php3 - Patch, Vendor Advisory | |
References | () http://www.osvdb.org/6282 - | |
References | () http://www.redhat.com/support/errata/RHSA-2000-125.html - | |
References | () http://www.zope.org/Products/Zope/Hotfix_2000-12-08/security_alert - Patch, Vendor Advisory |
Information
Published : 2000-12-16 05:00
Updated : 2024-11-20 23:34
NVD link : CVE-2000-1211
Mitre link : CVE-2000-1211
CVE.ORG link : CVE-2000-1211
JSON object : View
Products Affected
zope
- zope
CWE