CVE-2005-3323
published 2005-10-27CVE-2005-3323: docutils in Zope 2.6, 2.7 before 2.7.8, and 2.8 before 2.8.2 allows remote attackers to include arbitrary files via include directives in RestructuredText…
PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.05%
86.1th percentile
docutils in Zope 2.6, 2.7 before 2.7.8, and 2.8 before 2.8.2 allows remote attackers to include arbitrary files via include directives in RestructuredText functionality.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| zope | zope | — | — |
| zope | zope | >= 2.7.0 < 2.7.8 | 2.7.8 |
| zope | zope | >= 2.8.0 < 2.8.2 | 2.8.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Zope vulnerability
vendor_ubuntu·2005-12-14
CVE-2005-3323 Zope vulnerability
Title: Zope vulnerability
Summary: Zope vulnerability
Zope did not deactivate the file inclusion feature when exposing
RestructuredText functionalities to untrusted users. A remote user
with the privilege of editing Zope webpages with RestructuredText
could exploit this to expose arbitrary files that can be read with the
privileges of the Zope server, or execute arbitrary Zope code.
Instructions: In general, a standard system update will make all the necessary changes.
GHSA
GHSA-r5w9-hv7v-5mpj: docutils in Zope 2
ghsa_unreviewed·2022-05-01
CVE-2005-3323 [HIGH] GHSA-r5w9-hv7v-5mpj: docutils in Zope 2
docutils in Zope 2.6, 2.7 before 2.7.8, and 2.8 before 2.8.2 allows remote attackers to include arbitrary files via include directives in RestructuredText functionality.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/17173http://secunia.com/advisories/17309http://secunia.com/advisories/17676http://www.debian.org/security/2005/dsa-910http://www.gentoo.org/security/en/glsa/glsa-200510-20.xmlhttp://www.novell.com/linux/security/advisories/2005_27_sr.htmlhttp://www.securityfocus.com/bid/15082http://www.zope.org/Products/Zope/Hotfix_2005-10-09/security_alerthttps://usn.ubuntu.com/229-1/http://secunia.com/advisories/17173http://secunia.com/advisories/17309http://secunia.com/advisories/17676http://www.debian.org/security/2005/dsa-910http://www.gentoo.org/security/en/glsa/glsa-200510-20.xmlhttp://www.novell.com/linux/security/advisories/2005_27_sr.htmlhttp://www.securityfocus.com/bid/15082http://www.zope.org/Products/Zope/Hotfix_2005-10-09/security_alerthttps://usn.ubuntu.com/229-1/
2005-10-27
Published