Vulnerabilities > Zope > Zope > 2.7.7

DATE CVE VULNERABILITY TITLE RISK
2006-07-07 CVE-2006-3458 Information Disclosure vulnerability in Zope Docutils
Zope 2.7.0 to 2.7.8, 2.8.0 to 2.8.7, and 2.9.0 to 2.9.3 (Zope2) does not disable the "raw" command when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows local users to read arbitrary files.
local
low complexity
zope
2.1
2005-10-27 CVE-2005-3323 docutils in Zope 2.6, 2.7 before 2.7.8, and 2.8 before 2.8.2 allows remote attackers to include arbitrary files via include directives in RestructuredText functionality.
network
low complexity
zope debian
7.5