Vulnerability Description
Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zope | Zope | 2.2.0 |
References
- http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-080.php3Patch
- http://www.redhat.com/support/errata/RHSA-2001-072.html
- http://www.redhat.com/support/errata/RHSA-2001-115.htmlPatch
- http://www.securityfocus.com/bid/3425
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7271
- http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-080.php3Patch
- http://www.redhat.com/support/errata/RHSA-2001-072.html
- http://www.redhat.com/support/errata/RHSA-2001-115.htmlPatch
- http://www.securityfocus.com/bid/3425
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7271
FAQ
What is CVE-2001-1227?
CVE-2001-1227 is a vulnerability with a CVSS score of 7.5 (HIGH). Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.
How severe is CVE-2001-1227?
CVE-2001-1227 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-1227?
Check the references section above for vendor advisories and patch information. Affected products include: Zope Zope.