CVE-2000-0725
N/A
N/A
Summary
Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by modifying the roles list that is included in a request.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://archives.neohapsis.com/archives/bugtraq/2000-08/0259.html
- http://www.debian.org/security/2000/20000821
- http://www.securityfocus.com/bid/1577
- http://www.zope.org/Products/Zope/Hotfix_08_09_2000/security_alert
- http://www.redhat.com/support/errata/RHSA-2000-052.html
- http://archives.neohapsis.com/archives/bugtraq/2000-08/0198.html
References
- http://archives.neohapsis.com/archives/bugtraq/2000-08/0259.html
- http://www.debian.org/security/2000/20000821
- http://www.securityfocus.com/bid/1577
- http://www.zope.org/Products/Zope/Hotfix_08_09_2000/security_alert
- http://www.redhat.com/support/errata/RHSA-2000-052.html
- http://archives.neohapsis.com/archives/bugtraq/2000-08/0198.html
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.