CVE-2002-0688
EPSS 0.60%ZCatalog plug-in for Zope allows anonymous users to bypass access restrictions
發布日:2022/4/30修改日:2024/2/12
描述
ZCatalog plug-in index support capability for Zope 2.4.0 through 2.5.1 allows anonymous users and untrusted code to bypass access restrictions and call arbitrary methods of catalog indexes.
受影響套件(2)
- Debian/zopefrom 0, < 2.5.1-1woody1
- PyPI/zope>= 2.4.0, < 2.6.0
參考連結(6)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2002-0688
- WEBhttps://web.archive.org/web/20020810160608/http://www.zope.org/Products/Zope/Hotfix_2002-06-14/security_alert
- WEBhttps://web.archive.org/web/20020822025750/http://www.iss.net/security_center/static/9610.php
- WEBhttps://web.archive.org/web/20021206023914/http://rhn.redhat.com/errata/RHSA-2002-060.html
- WEBhttps://web.archive.org/web/20021223212650/http://online.securityfocus.com/bid/5812
- WEBhttps://web.archive.org/web/20070430090648/http://www.debian.org/security/2004/dsa-490