CVE
- Id
- 4082
- CVE No.
- CVE-2001-1278
- Status
- Candidate
- Description
- Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.
- Phase
- Proposed (20020502)
- Votes
- ACCEPT(3) Cole, Green, Wall | NOOP(1) Foat | REJECT(3) Christey, Cox, Frech
- Comments
- Christey> Agreed; dupe of CVE-2001-1227