Vulnerabilities > Zope > Zope > 2.9.3
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2007-03-22 | CVE-2007-0240 | HTML Injection vulnerability in Zope HTTP Get Request Cross-site scripting (XSS) vulnerability in Zope 2.10.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a HTTP GET request. network zope | 4.3 |
2006-07-07 | CVE-2006-3458 | Information Disclosure vulnerability in Zope Docutils Zope 2.7.0 to 2.7.8, 2.8.0 to 2.8.7, and 2.9.0 to 2.9.3 (Zope2) does not disable the "raw" command when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows local users to read arbitrary files. | 2.1 |