Vulnerabilities > CVE-2000-1212 - Unspecified vulnerability in Zope

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
zope
nessus

Summary

Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects.

Nessus

  • NASL familyWeb Servers
    NASL idZOPE_IMG_UPDATING.NASL
    descriptionAccording to its banner, the remote web server is Zope < 2.2.5. Such versions suffer from a security issue involving incorrect protection of a data updating method on Image and File objects. Because the method is not correctly protected, it is possible for users with DTML editing privileges to update the raw data of a File or Image object via DTML though they do not have editing privileges on the objects themselves. *** Since Nessus solely relied on the version number of the server, *** consider this a false positive if the hotfix has already been applied.
    last seen2020-06-01
    modified2020-06-02
    plugin id10569
    published2000-12-19
    reporterThis script is Copyright (C) 2000-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/10569
    titleZope Image and File Update Data Protection Bypass
  • NASL familyMandriva Local Security Checks
    NASL idMANDRAKE_MDKSA-2000-086.NASL
    descriptionA potential security issue exists in versions of Zope up to and including 2.2.4. This issue involves incorrect protection of a data updating method on Image and File objects. Because the method was not correctly protected, it was possible for users with DTML editing privileges to update the raw data of a File or Image object via DTML though they did not have editing privileges on the objects themselves. This update replaces the previous Zope update noted in MDKSA-2000:083.
    last seen2020-06-01
    modified2020-06-02
    plugin id61872
    published2012-09-06
    reporterThis script is Copyright (C) 2012-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/61872
    titleMandrake Linux Security Advisory : Zope (MDKSA-2000:086)

Redhat

advisories
rhsa
idRHSA-2000:135