Page 2 of 17 results (0.002 seconds)

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

22 Mar 2007 — Cross-site scripting (XSS) vulnerability in Zope 2.10.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a HTTP GET request. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Zope 2.10.2 y versiones anteriores permite a atacantes remotos inyectar scripts web o HTML de su elección mediante vectores sin especificar en una petición HTTP GET. • http://lists.suse.com/archive/suse-security-announce/2007-May/0005.html •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

23 Jul 2002 — The "through the web code" capability for Zope 2.0 through 2.5.1 b1 allows untrusted users to shut down the Zope server via certain headers. La capacidad through the web code de Zope desde la versión 2.0 a la 2.5.1 b1, permite a usuarios no fiables parar el servidor mediante ciertas cabeceras. • http://www.iss.net/security_center/static/9621.php •

CVSS: 2.1EPSS: 0%CPEs: 1EXPL: 0

27 Jul 2001 — Digital Creations Zope 2.3.1 b1 and earlier allows a local attacker (Zope user) with through-the-web scripting capabilities to alter ZClasses class attributes. • http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000382 •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

27 Jul 2001 — Digital Creations Zope 2.3.1 b1 and earlier contains a problem in the method return values related to the classes (1) ObjectManager, (2) PropertyManager, and (3) PropertySheet. • http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000382 •

CVSS: 7.8EPSS: 0%CPEs: 15EXPL: 0

12 Mar 2001 — Zope before 2.2.4 does not properly compute local roles, which could allow users to bypass specified access restrictions and gain privileges. • ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:06.zope.asc •

CVSS: 8.1EPSS: 0%CPEs: 4EXPL: 0

13 Oct 2000 — Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by modifying the roles list that is included in a request. • http://archives.neohapsis.com/archives/bugtraq/2000-08/0198.html •

CVSS: 7.5EPSS: 1%CPEs: 5EXPL: 0

15 Jun 2000 — The DocumentTemplate package in Zope 2.2 and earlier allows a remote attacker to modify DTMLDocuments or DTMLMethods without authorization. • ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00%3A38.zope.asc •