CVE-2000-1212

Zope 2.2.0-2.2.4 - Authenticated Arbitrary File Write via Image and File Object Data Update

Title source: llm
STIX 2.1

Description

Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects.

References (7)

Core 7
Core References
Patch, Vendor Advisory x_refsource_confirm
http://www.zope.org/Products/Zope/Hotfix_2000-12-18/security_alert
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2000-135.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/5778
Various Sources vendor-advisory x_refsource_mandrake
http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:086
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2001/dsa-007
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/6283
Vendor Advisory vendor-advisory x_refsource_conectiva
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000365

Scores

EPSS 0.0153
EPSS Percentile 72.1%

Details

Status published
Products (12)
pypi/zope 2.2.0PyPI
zope/zope 2.2.0
zope/zope 2.2.0a1
zope/zope 2.2.0b1
zope/zope 2.2.0b2
zope/zope 2.2.0b3
zope/zope 2.2.0b4
zope/zope 2.2.1
zope/zope 2.2.1b1
zope/zope 2.2.2
... and 2 more
Published Dec 18, 2000
Tracked Since Feb 18, 2026