Executive Summary
Summary | |
---|---|
Title | New zope2.7 packages fix cross-site scripting flaw |
Informations | |||
---|---|---|---|
Name | DSA-1275 | First vendor Publication | 2007-04-02 |
Vendor | Debian | Last vendor Modification | 2007-04-02 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:N/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 4.3 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
A cross-site scripting vulnerability in zope, a web application server, could allow an attacker to inject arbitrary HTML and/or JavaScript into the victim's web browser. This code would run within the security context of the web browser, potentially allowing the attacker to access private data such as authentication cookies, or to affect the rendering or behavior of zope web pages. For the stable distribution (sarge), this problem has been fixed in version 2.7.5-2sarge4 The upcoming stable distribution (etch) and the unstable distribution (sid) include zope2.9, and this vulnerability is fixed in version 2.9.6-4etch1 for etch and 2.9.7-1 for sid. We recommend that you upgrade your zope2.7 package. |
Original Source
Url : http://www.debian.org/security/2007/dsa-1275 |
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2008-09-04 | Name : FreeBSD Ports: zope File : nvt/freebsd_zope1.nasl |
2008-01-17 | Name : Debian Security Advisory DSA 1275-1 (zope2.7) File : nvt/deb_1275_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
34366 | Zope Unspecified HTTP GET Request CSRF |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2007-10-17 | Name : The remote openSUSE host is missing a security update. File : suse_zope-3346.nasl - Type : ACT_GATHER_INFO |
2007-04-10 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1275.nasl - Type : ACT_GATHER_INFO |
2007-04-10 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_34414a1ee37711dbb8ab000c76189c4c.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:26:33 |
|