积极预防 及时发现
快速响应 力保恢复
Zope 2.2.1之前的版本没有完全限制对getRoles方法的访问,这导致可以编辑DTML的用户...
发布时间:2002-05-20 信息来源:管理员

CNCVE编号:CNCVE-20000725 CVE编号:CVE-2000-0725 安全级别:中 漏洞中文描述: Zope 2.2.1之前的版本没有完全限制对getRoles方法的访问,这导致可以编辑DTML的用户通过修改包括在一个请求中的任务列表来增加或者修改任务。 漏洞英文描述: Zope before 2.2.1 does not properly restrict access to the getRoles method, which allows users who can edit DTML to add or modify roles by modifying the roles list that is included in a request. 漏洞参考: 系统类型:其他 漏洞类型:其他