| Vulnerability Name: | CVE-2006-4684 (CCN-28987) | ||||||||||||
| Assigned: | 2006-08-21 | ||||||||||||
| Published: | 2006-08-21 | ||||||||||||
| Updated: | 2011-03-08 | ||||||||||||
| Summary: | The docutils module in Zope (Zope2) 2.7.0 through 2.7.9 and 2.8.0 through 2.8.8 does not properly handle web pages with reStructuredText (reST) markup, which allows remote attackers to read arbitrary files via a csv_table directive, a different vulnerability than CVE-2006-3458. | ||||||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||||||
| Vulnerability Type: | CWE-Other | ||||||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2006-4684 Source: CCN Type: Zope-Annce Mailing List, Mon Aug 21 16:06:38 EDT 2006 Hotfix for Further reST Integration Issue Source: MLIST Type: UNKNOWN [Zope-Annce] 20060821 Hotfix for Further reST Integration Issue Source: CCN Type: SA21947 Zope restructuredText "csv_table" Information Disclosure Source: SECUNIA Type: Patch, Vendor Advisory 21947 Source: SECUNIA Type: Patch, Vendor Advisory 21953 Source: DEBIAN Type: Patch, Vendor Advisory DSA-1176 Source: DEBIAN Type: DSA-1176 zope2.7 -- programming error Source: BID Type: UNKNOWN 20022 Source: CCN Type: BID-20022 Zope CSV_Table Information Disclosure Vulnerability Source: VUPEN Type: UNKNOWN ADV-2006-3653 Source: CCN Type: Zope Web site Hotfix-20060821 README Source: CONFIRM Type: Patch http://www.zope.org/Products/Zope/Hotfix-2006-08-21/Hotfix-20060821/README.txt Source: XF Type: UNKNOWN zope-docutils-csvtable-info-disclosure(28987) | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
| Oval Definitions | |||||||||||||
| |||||||||||||
| BACK | |||||||||||||