CNCVE编号:CNCVE-20000725 CVE编号:CVE-2000-0725 安全级别:中 漏洞中文描述: Zope 2.2.1之前的版本没有完全限制对getRoles方法的访问,这导致可以编辑DTML的用户通过修改包括在一个请求中的任务列表来增加或者修改任务。 漏洞英文描述: Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by modifying the roles list that is included in a request. 漏洞参考: 系统类型:其他 漏洞类型:其他