7.5
CVSSv2

CVE-2002-0688

Published: 23/07/2002 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

ZCatalog plug-in index support capability for Zope 2.4.0 up to and including 2.5.1 allows anonymous users and untrusted code to bypass access restrictions and call arbitrary methods of catalog indexes.

Vulnerable Product Search on Vulmon Subscribe to Product

zope zope 2.5.1

zope zope 2.4.0

Vendor Advisories

A vulnerability has been discovered in the index support of the ZCatalog plug-in in Zope, an open source web application server A flaw in the security settings of ZCatalog allows anonymous users to call arbitrary methods of catalog indexes The vulnerability also allows untrusted code to do the same For the stable distribution (woody) this proble ...