CVE Database
/

CVE-2006-3458

Back to search

CVE-2006-3458

Published: Jul 7, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Zope 2.7.0 to 2.7.8, 2.8.0 to 2.8.7, and 2.9.0 to 2.9.3 (Zope2) does not disable the "raw" command when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows local users to read arbitrary files.

VendorProductVersions

n/a

n/a

affected
n/a

References

21025
third-party-advisory
x_refsource_SECUNIA
ADV-2006-2681
vdb-entry
x_refsource_VUPEN
21130
third-party-advisory
x_refsource_SECUNIA
21459
third-party-advisory
x_refsource_SECUNIA
SUSE-SR:2006:019
vendor-advisory
x_refsource_SUSE
DSA-1113
vendor-advisory
x_refsource_DEBIAN
18856
vdb-entry
x_refsource_BID
20988
third-party-advisory
x_refsource_SECUNIA
USN-317-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now