2.1
CVSSv2

CVE-2006-3458

Published: 07/07/2006 Updated: 03/10/2018
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Zope 2.7.0 to 2.7.8, 2.8.0 to 2.8.7, and 2.9.0 to 2.9.3 (Zope2) does not disable the "raw" command when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows local users to read arbitrary files.

Vulnerable Product Search on Vulmon Subscribe to Product

zope zope 2.7.4

zope zope 2.7.5

zope zope 2.8.3

zope zope 2.7.0

zope zope 2.7.1

zope zope 2.7.8

zope zope 2.8.0

zope zope 2.9.0

zope zope 2.9.1

zope zope 2.7.6

zope zope 2.7.7

zope zope 2.8.5

zope zope 2.8.6

zope zope 2.8.7

zope zope 2.8.4

zope zope 2.7.2

zope zope 2.7.3

zope zope 2.8.1

zope zope 2.8.2

zope zope 2.9.2

zope zope 2.9.3

Vendor Advisories

Zope did not deactivate the ‘raw’ command when exposing RestructuredText functionalities to untrusted users A remote user with the privilege of editing Zope webpages with RestructuredText could exploit this to expose arbitrary files that can be read with the privileges of the Zope server ...