VDB
CVE-2008-5102
CVE-2008-5102
PUBLISHED
CVSS 4 MEDIUM
PythonScripts in Zope 2 2.11.2 and earlier, as used in Conga and other products, allows remote authenticated users to cause a denial of service (resource consumption or application halt) via certain (1) raise or (2) import statements.
EPSS 12.10% · 93.9th percentile
Risk Scores
CVSS 2.0
4
EPSS Score
12.10%
93.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| zope | zope | 2.7.4-c1, 0, 1.10.3 |
| n/a | n/a | n/a |
Timeline
- Nov 17, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- [Zope] 20080812 Script (Python) insecure ? mailing-list
- http://bugs.gentoo.org/show_bug.cgi?id=246411 url
- https://bugs.launchpad.net/zope2/+bug/257269 url
- http://www.zope.org/Products/Zope/Hotfix-2008-08-12/README.txt url
- http://www.zope.org/Products/Zope/Hotfix-2008-08-12/Hotfix_20080812-1.1.0.tar.gz url
- https://bugs.launchpad.net/zope2/+bug/257276 url
- ADV-2008-2418 vdb
- [oss-security] 20081112 CVE Request - Zope 2 - PythonScripts local DoS mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2008-5102 advisory