Zope 2.7.0 to 2.7.8, 2.8.0 to 2.8.7, and 2.9.0 to 2.9.3 (Zope2) does not disable the "raw" command when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows local users to read arbitrary files.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2006-07-07 16:05
Updated : 2018-10-03 14:43
NVD link : CVE-2006-3458
Mitre link : CVE-2006-3458
JSON object : View
CWE
Products Affected
zope
- zope