Vulnerability Details CVE-2006-3458
Zope 2.7.0 to 2.7.8, 2.8.0 to 2.8.7, and 2.9.0 to 2.9.3 (Zope2) does not disable the "raw" command when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows local users to read arbitrary files.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 29.5%
CVSS Severity
CVSS v2 Score 2.1
Products affected by CVE-2006-3458
-
cpe:2.3:a:zope:zope:2.7.0
-
cpe:2.3:a:zope:zope:2.7.1
-
cpe:2.3:a:zope:zope:2.7.2
-
cpe:2.3:a:zope:zope:2.7.3
-
cpe:2.3:a:zope:zope:2.7.4
-
cpe:2.3:a:zope:zope:2.7.5
-
cpe:2.3:a:zope:zope:2.7.6
-
cpe:2.3:a:zope:zope:2.7.7
-
cpe:2.3:a:zope:zope:2.7.8
-
cpe:2.3:a:zope:zope:2.8.0
-
cpe:2.3:a:zope:zope:2.8.1
-
cpe:2.3:a:zope:zope:2.8.2
-
cpe:2.3:a:zope:zope:2.8.3
-
cpe:2.3:a:zope:zope:2.8.4
-
cpe:2.3:a:zope:zope:2.8.5
-
cpe:2.3:a:zope:zope:2.8.6
-
cpe:2.3:a:zope:zope:2.8.7
-
cpe:2.3:a:zope:zope:2.9.0
-
cpe:2.3:a:zope:zope:2.9.1
-
cpe:2.3:a:zope:zope:2.9.2
-
cpe:2.3:a:zope:zope:2.9.3