5

CVE-2000-1212

Zope 2.2.0 through 2.2.4 does not properly protect a data updating method on Image and File objects, which allows attackers with DTML editing privileges to modify the raw data of these objects.

Data is provided by the National Vulnerability Database (NVD)
ZopeZope Version2.2.0
ZopeZope Version2.2.0a1
ZopeZope Version2.2.0b1
ZopeZope Version2.2.0b2
ZopeZope Version2.2.0b3
ZopeZope Version2.2.0b4
ZopeZope Version2.2.1
ZopeZope Version2.2.1b1
ZopeZope Version2.2.2
ZopeZope Version2.2.3
ZopeZope Version2.2.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.86% 0.73
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N