CVE-2006-4684
Summary
| CVE | CVE-2006-4684 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-09-19 18:07:00 UTC |
| Updated | 2011-03-08 02:41:00 UTC |
| Description | The docutils module in Zope (Zope2) 2.7.0 through 2.7.9 and 2.8.0 through 2.8.8 does not properly handle web pages with reStructuredText (reST) markup, which allows remote attackers to read arbitrary files via a csv_table directive, a different vulnerability than CVE-2006-3458. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Zope | Zope | 2.7.0 | All | All | All |
| Application | Zope | Zope | 2.7.1 | All | All | All |
| Application | Zope | Zope | 2.7.2 | All | All | All |
| Application | Zope | Zope | 2.7.3 | All | All | All |
| Application | Zope | Zope | 2.7.4 | All | All | All |
| Application | Zope | Zope | 2.7.5 | All | All | All |
| Application | Zope | Zope | 2.7.6 | All | All | All |
| Application | Zope | Zope | 2.7.7 | All | All | All |
| Application | Zope | Zope | 2.7.8 | All | All | All |
| Application | Zope | Zope | 2.7.9 | All | All | All |
| Application | Zope | Zope | 2.8.0 | All | All | All |
| Application | Zope | Zope | 2.8.1 | All | All | All |
| Application | Zope | Zope | 2.8.2 | All | All | All |
| Application | Zope | Zope | 2.8.3 | All | All | All |
| Application | Zope | Zope | 2.8.4 | All | All | All |
| Application | Zope | Zope | 2.8.5 | All | All | All |
| Application | Zope | Zope | 2.8.6 | All | All | All |
| Application | Zope | Zope | 2.8.7 | All | All | All |
| Application | Zope | Zope | 2.8.8 | All | All | All |
| Application | Zope | Zope | 2.7.0 | All | All | All |
| Application | Zope | Zope | 2.7.1 | All | All | All |
| Application | Zope | Zope | 2.7.2 | All | All | All |
| Application | Zope | Zope | 2.7.3 | All | All | All |
| Application | Zope | Zope | 2.7.4 | All | All | All |
| Application | Zope | Zope | 2.7.5 | All | All | All |
| Application | Zope | Zope | 2.7.6 | All | All | All |
| Application | Zope | Zope | 2.7.7 | All | All | All |
| Application | Zope | Zope | 2.7.8 | All | All | All |
| Application | Zope | Zope | 2.7.9 | All | All | All |
| Application | Zope | Zope | 2.8.0 | All | All | All |
| Application | Zope | Zope | 2.8.1 | All | All | All |
| Application | Zope | Zope | 2.8.2 | All | All | All |
| Application | Zope | Zope | 2.8.3 | All | All | All |
| Application | Zope | Zope | 2.8.4 | All | All | All |
| Application | Zope | Zope | 2.8.5 | All | All | All |
| Application | Zope | Zope | 2.8.6 | All | All | All |
| Application | Zope | Zope | 2.8.7 | All | All | All |
| Application | Zope | Zope | 2.8.8 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Zope CSV_Table Information Disclosure Vulnerability | BID | www.securityfocus.com | |
| 404 Not Found | CONFIRM | www.zope.org | Patch |
| Zope restructuredText "csv_table" Information Disclosure - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Debian update for zope2.7 - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| [Zope-Annce] Hotfix for Further reST Integration Issue | MLIST | mail.zope.org | |
| Debian -- Security Information -- DSA-1176-1 zope2.7 | DEBIAN | www.debian.org | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.