Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2008-5102
Disclosure Date: November 17, 2008 (last updated October 04, 2023)
PythonScripts in Zope 2 2.11.2 and earlier, as used in Conga and other products, allows remote authenticated users to cause a denial of service (resource consumption or application halt) via certain (1) raise or (2) import statements.
0
Attacker Value
Unknown
CVE-2002-0170
Disclosure Date: April 22, 2002 (last updated February 22, 2025)
Zope 2.2.0 through 2.5.1 does not properly verify the access for objects with proxy roles, which could allow some users to access documents in violation of the intended configuration.
0
Attacker Value
Unknown
CVE-2001-1227
Disclosure Date: October 10, 2001 (last updated February 22, 2025)
Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.
0
Attacker Value
Unknown
CVE-2001-1278
Disclosure Date: October 10, 2001 (last updated February 22, 2025)
Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.
0
Attacker Value
Unknown
CVE-2000-1212
Disclosure Date: December 18, 2000 (last updated February 22, 2025)
Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects.
0
Attacker Value
Unknown
CVE-2000-1211
Disclosure Date: December 16, 2000 (last updated February 22, 2025)
Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which could allow attackers to perform unauthorized activities.
0