Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2006-3458
Description:Zope 2.7.0 to 2.7.8, 2.8.0 to 2.8.7, and 2.9.0 to 2.9.3 (Zope2) does not disable the "raw" command when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows local users to read arbitrary files.
Test IDs: 1.3.6.1.4.1.25623.1.0.57148   1.3.6.1.4.1.25623.1.0.57103   1.3.6.1.4.1.25623.1.1.12.2006.317.1   1.3.6.1.4.1.25623.1.0.57115  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2006-3458
BugTraq ID: 18856
http://www.securityfocus.com/bid/18856
Debian Security Information: DSA-1113 (Google Search)
http://www.debian.org/security/2006/dsa-1113
http://mail.zope.org/pipermail/zope-announce/2006-July/001984.html
http://secunia.com/advisories/20988
http://secunia.com/advisories/21025
http://secunia.com/advisories/21130
http://secunia.com/advisories/21459
SuSE Security Announcement: SUSE-SR:2006:019 (Google Search)
http://www.novell.com/linux/security/advisories/2006_19_sr.html
https://usn.ubuntu.com/317-1/
http://www.vupen.com/english/advisories/2006/2681
XForce ISS Database: zope-docutils-information-disclosure(27636)
https://exchange.xforce.ibmcloud.com/vulnerabilities/27636




© 1998-2025 E-Soft Inc. All rights reserved.