CVE-2000-1212
Zope 2.2.0-2.2.4 - Authenticated Arbitrary File Write via Image and File Object Data Update
Title source: llmDescription
Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects.
References (7)
Core 7
Core References
Patch, Vendor Advisory x_refsource_confirm
http://www.zope.org/Products/Zope/Hotfix_2000-12-18/security_alert
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2000-135.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/5778
Various Sources vendor-advisory
x_refsource_mandrake
http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:086
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2001/dsa-007
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/6283
Vendor Advisory vendor-advisory
x_refsource_conectiva
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000365
Scores
EPSS
0.0153
EPSS Percentile
72.1%
Details
Status
published
Products (12)
pypi/zope
2.2.0PyPI
zope/zope
2.2.0
zope/zope
2.2.0a1
zope/zope
2.2.0b1
zope/zope
2.2.0b2
zope/zope
2.2.0b3
zope/zope
2.2.0b4
zope/zope
2.2.1
zope/zope
2.2.1b1
zope/zope
2.2.2
... and 2 more
Published
Dec 18, 2000
Tracked Since
Feb 18, 2026