Mandrake Linux Security Advisory : Zope (MDKSA-2000:086)

This script is Copyright (C) 2012-2013 Tenable Network Security, Inc.

Synopsis :

The remote Mandrake Linux host is missing one or more security

Description :

A potential security issue exists in versions of Zope up to and
including 2.2.4. This issue involves incorrect protection of a data
updating method on Image and File objects. Because the method was not
correctly protected, it was possible for users with DTML editing
privileges to update the raw data of a File or Image object via DTML
though they did not have editing privileges on the objects themselves.
This update replaces the previous Zope update noted in MDKSA-2000:083.

Solution :

Update the affected packages.

Risk factor :

High / CVSS Base Score : 7.2

Family: Mandriva Local Security Checks

Nessus Plugin ID: 61872 ()

Bugtraq ID:

CVE ID: CVE-2000-1212

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now