Vulnerabilities > CVE-2000-1212 - Unspecified vulnerability in Zope

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
zope
nessus

Summary

Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects.

Nessus

  • NASL familyWeb Servers
    NASL idZOPE_IMG_UPDATING.NASL
    descriptionAccording to its banner, the remote web server is Zope < 2.2.5. Such versions suffer from a security issue involving incorrect protection of a data updating method on Image and File objects. Because the method is not correctly protected, it is possible for users with DTML editing privileges to update the raw data of a File or Image object via DTML though they do not have editing privileges on the objects themselves. *** Since Nessus solely relied on the version number of the server, *** consider this a false positive if the hotfix has already been applied.
    last seen2020-06-01
    modified2020-06-02
    plugin id10569
    published2000-12-19
    reporterThis script is Copyright (C) 2000-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/10569
    titleZope Image and File Update Data Protection Bypass
  • NASL familyMandriva Local Security Checks
    NASL idMANDRAKE_MDKSA-2000-086.NASL
    descriptionA potential security issue exists in versions of Zope up to and including 2.2.4. This issue involves incorrect protection of a data updating method on Image and File objects. Because the method was not correctly protected, it was possible for users with DTML editing privileges to update the raw data of a File or Image object via DTML though they did not have editing privileges on the objects themselves. This update replaces the previous Zope update noted in MDKSA-2000:083.
    last seen2020-06-01
    modified2020-06-02
    plugin id61872
    published2012-09-06
    reporterThis script is Copyright (C) 2012-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/61872
    titleMandrake Linux Security Advisory : Zope (MDKSA-2000:086)

Redhat

advisories
rhsa
idRHSA-2000:135