Show filters
53 Total Results
Displaying 31-40 of 53
Sort by:
Attacker Value
Unknown
CVE-2010-1104
Disclosure Date: March 25, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3 allows remote attackers to inject arbitrary web script or HTML via vectors related to error messages.
0
Attacker Value
Unknown
CVE-2009-2701
Disclosure Date: September 08, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the Zope Enterprise Objects (ZEO) storage-server functionality in Zope Object Database (ZODB) 3.8 before 3.8.3 and 3.9.x before 3.9.0c2, when certain ZEO database sharing and blob support are enabled, allows remote authenticated users to read or delete arbitrary files via unknown vectors.
0
Attacker Value
Unknown
CVE-2009-0668
Disclosure Date: August 07, 2009 (last updated October 04, 2023)
Unspecified vulnerability in Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows remote attackers to execute arbitrary Python code via vectors involving the ZEO network protocol.
0
Attacker Value
Unknown
CVE-2009-0669
Disclosure Date: August 07, 2009 (last updated October 04, 2023)
Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows remote attackers to bypass authentication via vectors involving the ZEO network protocol.
0
Attacker Value
Unknown
CVE-2008-5102
Disclosure Date: November 17, 2008 (last updated October 04, 2023)
PythonScripts in Zope 2 2.11.2 and earlier, as used in Conga and other products, allows remote authenticated users to cause a denial of service (resource consumption or application halt) via certain (1) raise or (2) import statements.
0
Attacker Value
Unknown
CVE-2007-0240
Disclosure Date: March 22, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Zope 2.10.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a HTTP GET request.
0
Attacker Value
Unknown
CVE-2006-4684
Disclosure Date: September 19, 2006 (last updated October 04, 2023)
The docutils module in Zope (Zope2) 2.7.0 through 2.7.9 and 2.8.0 through 2.8.8 does not properly handle web pages with reStructuredText (reST) markup, which allows remote attackers to read arbitrary files via a csv_table directive, a different vulnerability than CVE-2006-3458.
0
Attacker Value
Unknown
CVE-2006-3458
Disclosure Date: July 07, 2006 (last updated October 04, 2023)
Zope 2.7.0 to 2.7.8, 2.8.0 to 2.8.7, and 2.9.0 to 2.9.3 (Zope2) does not disable the "raw" command when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows local users to read arbitrary files.
0
Attacker Value
Unknown
CVE-2005-3323
Disclosure Date: October 27, 2005 (last updated February 22, 2025)
docutils in Zope 2.6, 2.7 before 2.7.8, and 2.8 before 2.8.2 allows remote attackers to include arbitrary files via include directives in RestructuredText functionality.
0
Attacker Value
Unknown
CVE-2002-0687
Disclosure Date: July 23, 2002 (last updated February 22, 2025)
The "through the web code" capability for Zope 2.0 through 2.5.1 b1 allows untrusted users to shut down the Zope server via certain headers.
0