漏洞信息详情
Zope +DTMLTemplates 和DTMLMethods远程修改漏洞
- CNNVD编号:CNNVD-200006-063
- 危害等级: 高危
- CVE编号:
CVE-2000-0483
- 漏洞类型:
访问验证错误
- 发布时间:
2000-06-15
- 威胁类型:
远程
- 更新时间:
2005-05-02
- 厂 商:
zope - 漏洞来源:
First exposed in a… -
漏洞简介
Zope 2.2和更早版本中DocumentTemplate包存在漏洞。远程攻击者利用此漏洞可以在无认证情况下修改 DTMLDocuments或DTMLMethods。
漏洞公告
Zope has released a hotfix. Red Had has released patches – see advisory reference RHSA-2000:38-01.
Zope Zope 2.1 .x
-
FreeBSD ports-3 zope-2.2.0.tgz
ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-3-stable/www/zop
e-2.2.0.tgz -
FreeBSD ports-4 alpha zope-2.2.0.tgz
ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/alpha/packages-4-stable/www/zo
pe-2.2.0.tgz -
FreeBSD ports-4 i386 zope-2.2.0.tgz
ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-4-stable/www/zop
e-2.2.0.tgz -
FreeBSD ports-5 alpha zope-2.2.0.tgz
ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/alpha/packages-5-current/www/z
ope-2.2.0.tgz -
FreeBSD ports-5 i386 zope-2.2.0.tgz
ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-5-current/www/zo
pe-2.2.0.tgz -
Zope Hotfix_06_16_2000.tgz
http://www.zope.org/Products/Zope/Hotfix_06_16_2000/Hotfix_06_16_2000.
tgz
Zope Zope 2.2 beta1
-
FreeBSD ports-3 zope-2.2.0.tgz
ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-3-stable/www/zop
e-2.2.0.tgz -
FreeBSD ports-4 alpha zope-2.2.0.tgz
ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/alpha/packages-4-stable/www/zo
pe-2.2.0.tgz -
FreeBSD ports-4 i386 zope-2.2.0.tgz
ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-4-stable/www/zop
e-2.2.0.tgz -
FreeBSD ports-5 alpha zope-2.2.0.tgz
ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/alpha/packages-5-current/www/z
ope-2.2.0.tgz -
FreeBSD ports-5 i386 zope-2.2.0.tgz
ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-5-current/www/zo
pe-2.2.0.tgz -
Zope Hotfix_06_16_2000.tgz
http://www.zope.org/Products/Zope/Hotfix_06_16_2000/Hotfix_06_16_2000.
tgz
参考网址
来源: www.zope.org
链接:http://www.zope.org/Products/Zope/Hotfix_06_16_2000/security_alert
来源: BUGTRAQ
名称: 20000615 [Brian@digicool.com: [Zope] Zope security alert and 2.1.7 update [*important*]]
链接:http://archives.neohapsis.com/archives/bugtraq/2000-06/0144.html
来源: XF
名称: zope-dtml-remote-modify
链接:http://xforce.iss.net/static/4716.php
来源: BUGTRAQ
名称: 2000615 Conectiva Linux Security Announcement – ZOPE
链接:http://www.securityfocus.com/templates/archive.pike?list=1&msg=20000616103807.A3768@conectiva.com.br
来源: BID
名称: 1354
链接:http://www.securityfocus.com/bid/1354
来源: REDHAT
名称: RHSA-2000:038
链接:http://www.redhat.com/support/errata/RHSA-2000-038.html
来源: BUGTRAQ
名称: 20000728 MDKSA-2000:026 Zope update
链接:http://archives.neohapsis.com/archives/bugtraq/2000-07/0412.html
来源: FREEBSD
名称: FreeBSD-SA-00:38
链接:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00%3A38.zope.asc