Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2000-12-17 21:00
Updated : 2017-10-09 18:29
NVD link : CVE-2000-1212
Mitre link : CVE-2000-1212
JSON object : View
CWE
Products Affected
zope
- zope