CVE-2006-4684: Medium severity Zope Zope vulnerability
The docutils module in Zope (Zope2) 2.7.0 through 2.7.9 and 2.8.0 through 2.8.8 does not properly handle web pages with reStructuredText (reST) markup, which allows remote attackers to read arbitrary files via a csvtable directive, a different vulnerability than CVE-2006-3458.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4684?
CVE-2006-4684 has a moderate severity level as it allows remote attackers to read arbitrary files.
How do I fix CVE-2006-4684?
To fix CVE-2006-4684, you should upgrade to Zope version 2.8.9 or later.
Which versions of Zope are affected by CVE-2006-4684?
CVE-2006-4684 affects Zope versions 2.7.0 through 2.7.9 and 2.8.0 through 2.8.8.
Can CVE-2006-4684 lead to data exposure?
Yes, CVE-2006-4684 can lead to data exposure as it allows attackers to access arbitrary files on the server.
What is the exploit method for CVE-2006-4684?
The exploit method for CVE-2006-4684 involves using the csv_table directive in web pages with reStructuredText markup.