Show filters
38 Total Results
Displaying 21-30 of 38
Sort by:
Attacker Value
Unknown
CVE-2007-0240
Disclosure Date: March 22, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Zope 2.10.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a HTTP GET request.
0
Attacker Value
Unknown
CVE-2006-4684
Disclosure Date: September 19, 2006 (last updated October 04, 2023)
The docutils module in Zope (Zope2) 2.7.0 through 2.7.9 and 2.8.0 through 2.8.8 does not properly handle web pages with reStructuredText (reST) markup, which allows remote attackers to read arbitrary files via a csv_table directive, a different vulnerability than CVE-2006-3458.
0
Attacker Value
Unknown
CVE-2006-3458
Disclosure Date: July 07, 2006 (last updated October 04, 2023)
Zope 2.7.0 to 2.7.8, 2.8.0 to 2.8.7, and 2.9.0 to 2.9.3 (Zope2) does not disable the "raw" command when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows local users to read arbitrary files.
0
Attacker Value
Unknown
CVE-2005-3323
Disclosure Date: October 27, 2005 (last updated February 22, 2025)
docutils in Zope 2.6, 2.7 before 2.7.8, and 2.8 before 2.8.2 allows remote attackers to include arbitrary files via include directives in RestructuredText functionality.
0
Attacker Value
Unknown
CVE-2002-0687
Disclosure Date: July 23, 2002 (last updated February 22, 2025)
The "through the web code" capability for Zope 2.0 through 2.5.1 b1 allows untrusted users to shut down the Zope server via certain headers.
0
Attacker Value
Unknown
CVE-2002-0688
Disclosure Date: July 23, 2002 (last updated February 22, 2025)
ZCatalog plug-in index support capability for Zope 2.4.0 through 2.5.1 allows anonymous users and untrusted code to bypass access restrictions and call arbitrary methods of catalog indexes.
0
Attacker Value
Unknown
CVE-2002-0170
Disclosure Date: April 22, 2002 (last updated February 22, 2025)
Zope 2.2.0 through 2.5.1 does not properly verify the access for objects with proxy roles, which could allow some users to access documents in violation of the intended configuration.
0
Attacker Value
Unknown
CVE-2001-1227
Disclosure Date: October 10, 2001 (last updated February 22, 2025)
Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.
0
Attacker Value
Unknown
CVE-2001-1278
Disclosure Date: October 10, 2001 (last updated February 22, 2025)
Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.
0
Attacker Value
Unknown
CVE-2001-0569
Disclosure Date: August 22, 2001 (last updated February 22, 2025)
Digital Creations Zope 2.3.1 b1 and earlier contains a problem in the method return values related to the classes (1) ObjectManager, (2) PropertyManager, and (3) PropertySheet.
0