Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2008-5102

Disclosure Date: November 17, 2008 (last updated October 04, 2023)
PythonScripts in Zope 2 2.11.2 and earlier, as used in Conga and other products, allows remote authenticated users to cause a denial of service (resource consumption or application halt) via certain (1) raise or (2) import statements.
0
Attacker Value
Unknown

CVE-2002-0170

Disclosure Date: April 22, 2002 (last updated February 22, 2025)
Zope 2.2.0 through 2.5.1 does not properly verify the access for objects with proxy roles, which could allow some users to access documents in violation of the intended configuration.
0
Attacker Value
Unknown

CVE-2001-1227

Disclosure Date: October 10, 2001 (last updated February 22, 2025)
Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.
0
Attacker Value
Unknown

CVE-2001-1278

Disclosure Date: October 10, 2001 (last updated February 22, 2025)
Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.
0
Attacker Value
Unknown

CVE-2000-1212

Disclosure Date: December 18, 2000 (last updated February 22, 2025)
Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects.
0
Attacker Value
Unknown

CVE-2000-1211

Disclosure Date: December 16, 2000 (last updated February 22, 2025)
Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which could allow attackers to perform unauthorized activities.
0