
CVE-2007-0240
https://notcve.org/view.php?id=CVE-2007-0240
22 Mar 2007 — Cross-site scripting (XSS) vulnerability in Zope 2.10.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a HTTP GET request. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Zope 2.10.2 y versiones anteriores permite a atacantes remotos inyectar scripts web o HTML de su elección mediante vectores sin especificar en una petición HTTP GET. • http://lists.suse.com/archive/suse-security-announce/2007-May/0005.html •

CVE-2002-0687
https://notcve.org/view.php?id=CVE-2002-0687
23 Jul 2002 — The "through the web code" capability for Zope 2.0 through 2.5.1 b1 allows untrusted users to shut down the Zope server via certain headers. La capacidad through the web code de Zope desde la versión 2.0 a la 2.5.1 b1, permite a usuarios no fiables parar el servidor mediante ciertas cabeceras. • http://www.iss.net/security_center/static/9621.php •

CVE-2001-0568
https://notcve.org/view.php?id=CVE-2001-0568
27 Jul 2001 — Digital Creations Zope 2.3.1 b1 and earlier allows a local attacker (Zope user) with through-the-web scripting capabilities to alter ZClasses class attributes. • http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000382 •

CVE-2001-0569
https://notcve.org/view.php?id=CVE-2001-0569
27 Jul 2001 — Digital Creations Zope 2.3.1 b1 and earlier contains a problem in the method return values related to the classes (1) ObjectManager, (2) PropertyManager, and (3) PropertySheet. • http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000382 •

CVE-2001-0128
https://notcve.org/view.php?id=CVE-2001-0128
12 Mar 2001 — Zope before 2.2.4 does not properly compute local roles, which could allow users to bypass specified access restrictions and gain privileges. • ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:06.zope.asc •

CVE-2000-0725
https://notcve.org/view.php?id=CVE-2000-0725
13 Oct 2000 — Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by modifying the roles list that is included in a request. • http://archives.neohapsis.com/archives/bugtraq/2000-08/0198.html •

CVE-2000-0483
https://notcve.org/view.php?id=CVE-2000-0483
15 Jun 2000 — The DocumentTemplate package in Zope 2.2 and earlier allows a remote attacker to modify DTMLDocuments or DTMLMethods without authorization. • ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00%3A38.zope.asc •

CVE-2000-0062
https://notcve.org/view.php?id=CVE-2000-0062
04 Jan 2000 — The DTML implementation in the Z Object Publishing Environment (Zope) allows remote attackers to conduct unauthorized activities. • http://www.securityfocus.com/bid/922 •