icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons_061

Zope < 2.1.7 DocumentTemplate Unauthorized Modification

High

Synopsis

The remote host is vulnerable to a flaw which allows for the bypassing of authentication.

Description

The remote web server is running a version of Zope which is older than 2.1.7. There is a security problem in all the releases older than 2.1.7 which may allow the content of DTMLDocuments (or DTMLMethods) to be changed by any user without authentication.

Solution

Upgrade to Zope 2.1.7 or higher.