In association with heise online

19 September 2006, 09:56

CMS Zope discloses information

An update for the open source platform for content management systems Zope fixes a vulnerability in the docutils module. Using the csv_table directive for restructuring text, it could be possible to gain access to confidential data on a system. According to a bug report, however, only systems which allow non-authenticated users to generate text over the internet are at risk. Versions 2.7.0. to 2.7.9. and 2.8.0. to 2.8.8 are affected. The update also fixes a further, unspecified security problem.

See also:

(ehe)

  • Share this article
  • Twitter
  • Facebook
  • digg this
  • submit to slashdot
  • post to delicious
  • StumbleUpon
  • submit to reddit







The H open source

The H Security

The H Internet Toolkit