2.1
CVSSv2

CVE-2001-0568

Published: 22/08/2001 Updated: 05/09/2008
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Digital Creations Zope 2.3.1 b1 and previous versions allows a local attacker (Zope user) with through-the-web scripting capabilities to alter ZClasses class attributes.

Vulnerable Product Search on Vulmon Subscribe to Product

zope zope

Vendor Advisories

This advisory covers several vulnerabilities in Zope that have been addressed Hotfix 08_09_2000 "Zope security alert and hotfix product" The issue involves the fact that the getRoles method of user objects contained in the default UserFolder implementation returns a mutable Python type Because the mutable object is still associated ...