Mandrake Linux Security Advisory : Zope (MDKSA-2000:083)

This script is Copyright (C) 2012-2013 Tenable Network Security, Inc.


Synopsis :

The remote Mandrake Linux host is missing one or more security
updates.

Description :

There is an issue involving security registration of 'legacy' names
for certain object constructors such as the constructors for DTML
Method Objects. Security was not being applied correctly for the
legacy names, making it possible to call those constructors without
the permissions that should have been required. This vulnerability
could allow anonymous users with enough knowledge of Zope to
instantiate new DTML Method instances through the web.

Solution :

Update the affected packages.

Risk factor :

High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)

Family: Mandriva Local Security Checks

Nessus Plugin ID: 61869 ()

Bugtraq ID:

CVE ID: CVE-2000-1211

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now