Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.58327
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-1275-1)
Summary:The remote host is missing an update for the Debian 'zope2.7' package(s) announced via the DSA-1275-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'zope2.7' package(s) announced via the DSA-1275-1 advisory.

Vulnerability Insight:
A cross-site scripting vulnerability in zope, a web application server, could allow an attacker to inject arbitrary HTML and/or JavaScript into the victim's web browser. This code would run within the security context of the web browser, potentially allowing the attacker to access private data such as authentication cookies, or to affect the rendering or behavior of zope web pages.

For the stable distribution (sarge), this problem has been fixed in version 2.7.5-2sarge4.

The upcoming stable distribution (etch) and the unstable distribution (sid) include zope2.9, and this vulnerability is fixed in version 2.9.6-4etch1 for etch and 2.9.7-1 for sid.

We recommend that you upgrade your zope2.7 package.

Affected Software/OS:
'zope2.7' package(s) on Debian 3.1.

Solution:
Please install the updated package(s).

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2007-0240
BugTraq ID: 23084
http://www.securityfocus.com/bid/23084
Debian Security Information: DSA-1275 (Google Search)
http://www.debian.org/security/2007/dsa-1275
http://secunia.com/advisories/24017
http://secunia.com/advisories/24713
http://secunia.com/advisories/25239
SuSE Security Announcement: SUSE-SR:2007:011 (Google Search)
http://lists.suse.com/archive/suse-security-announce/2007-May/0005.html
http://www.vupen.com/english/advisories/2007/1041
XForce ISS Database: zope-unspecifiedget-xss(33187)
https://exchange.xforce.ibmcloud.com/vulnerabilities/33187
CopyrightCopyright (C) 2008 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.