Show filters
38 Total Results
Displaying 21-30 of 38
Sort by:
Attacker Value
Unknown

CVE-2007-0240

Disclosure Date: March 22, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Zope 2.10.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a HTTP GET request.
0
Attacker Value
Unknown

CVE-2006-4684

Disclosure Date: September 19, 2006 (last updated October 04, 2023)
The docutils module in Zope (Zope2) 2.7.0 through 2.7.9 and 2.8.0 through 2.8.8 does not properly handle web pages with reStructuredText (reST) markup, which allows remote attackers to read arbitrary files via a csv_table directive, a different vulnerability than CVE-2006-3458.
0
Attacker Value
Unknown

CVE-2006-3458

Disclosure Date: July 07, 2006 (last updated October 04, 2023)
Zope 2.7.0 to 2.7.8, 2.8.0 to 2.8.7, and 2.9.0 to 2.9.3 (Zope2) does not disable the "raw" command when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows local users to read arbitrary files.
0
Attacker Value
Unknown

CVE-2005-3323

Disclosure Date: October 27, 2005 (last updated February 22, 2025)
docutils in Zope 2.6, 2.7 before 2.7.8, and 2.8 before 2.8.2 allows remote attackers to include arbitrary files via include directives in RestructuredText functionality.
0
Attacker Value
Unknown

CVE-2002-0687

Disclosure Date: July 23, 2002 (last updated February 22, 2025)
The "through the web code" capability for Zope 2.0 through 2.5.1 b1 allows untrusted users to shut down the Zope server via certain headers.
0
Attacker Value
Unknown

CVE-2002-0688

Disclosure Date: July 23, 2002 (last updated February 22, 2025)
ZCatalog plug-in index support capability for Zope 2.4.0 through 2.5.1 allows anonymous users and untrusted code to bypass access restrictions and call arbitrary methods of catalog indexes.
0
Attacker Value
Unknown

CVE-2002-0170

Disclosure Date: April 22, 2002 (last updated February 22, 2025)
Zope 2.2.0 through 2.5.1 does not properly verify the access for objects with proxy roles, which could allow some users to access documents in violation of the intended configuration.
0
Attacker Value
Unknown

CVE-2001-1227

Disclosure Date: October 10, 2001 (last updated February 22, 2025)
Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.
0
Attacker Value
Unknown

CVE-2001-1278

Disclosure Date: October 10, 2001 (last updated February 22, 2025)
Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.
0
Attacker Value
Unknown

CVE-2001-0569

Disclosure Date: August 22, 2001 (last updated February 22, 2025)
Digital Creations Zope 2.3.1 b1 and earlier contains a problem in the method return values related to the classes (1) ObjectManager, (2) PropertyManager, and (3) PropertySheet.
0