Cross-site scripting (XSS) vulnerability in Zope 2.8.x before 2.8.12, 2.9.x before 2.9.12, 2.10.x before 2.10.11, 2.11.x before 2.11.6, and 2.12.x before 2.12.3 allows remote attackers to inject arbitrary web script or HTML via vectors related to error messages.
2010-03-25T17:30:00.390
2025-04-11T00:51:21.963
Deferred
CVSSv2: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | zope | zope | 2.8 | Yes |
| Application | zope | zope | 2.8.0 | Yes |
| Application | zope | zope | 2.8.0-a1 | Yes |
| Application | zope | zope | 2.8.0-a2 | Yes |
| Application | zope | zope | 2.8.0-b1 | Yes |
| Application | zope | zope | 2.8.0-b2 | Yes |
| Application | zope | zope | 2.8.0-final | Yes |
| Application | zope | zope | 2.8.1 | Yes |
| Application | zope | zope | 2.8.1-b1 | Yes |
| Application | zope | zope | 2.8.1-final | Yes |
| Application | zope | zope | 2.8.2 | Yes |
| Application | zope | zope | 2.8.3 | Yes |
| Application | zope | zope | 2.8.4 | Yes |
| Application | zope | zope | 2.8.5 | Yes |
| Application | zope | zope | 2.8.6 | Yes |
| Application | zope | zope | 2.8.7 | Yes |
| Application | zope | zope | 2.8.8 | Yes |
| Application | zope | zope | 2.8.9 | Yes |
| Application | zope | zope | 2.8.9.1 | Yes |
| Application | zope | zope | 2.8.10 | Yes |
| Application | zope | zope | 2.8.11 | Yes |
| Application | zope | zope | 2.9.0 | Yes |
| Application | zope | zope | 2.9.0-b1 | Yes |
| Application | zope | zope | 2.9.0-b2 | Yes |
| Application | zope | zope | 2.9.1 | Yes |
| Application | zope | zope | 2.9.2 | Yes |
| Application | zope | zope | 2.9.3 | Yes |
| Application | zope | zope | 2.9.4 | Yes |
| Application | zope | zope | 2.9.5 | Yes |
| Application | zope | zope | 2.9.6 | Yes |
| Application | zope | zope | 2.9.7 | Yes |
| Application | zope | zope | 2.9.8 | Yes |
| Application | zope | zope | 2.9.9 | Yes |
| Application | zope | zope | 2.9.10 | Yes |
| Application | zope | zope | 2.9.11 | Yes |
| Application | zope | zope | 2.10.0-b1 | Yes |
| Application | zope | zope | 2.10.0-b2 | Yes |
| Application | zope | zope | 2.10.0-c1 | Yes |
| Application | zope | zope | 2.10.0-final | Yes |
| Application | zope | zope | 2.10.2 | Yes |
| Application | zope | zope | 2.10.2-b1 | Yes |
| Application | zope | zope | 2.10.2-final | Yes |
| Application | zope | zope | 2.10.3 | Yes |
| Application | zope | zope | 2.10.3-final | Yes |
| Application | zope | zope | 2.10.4-final | Yes |
| Application | zope | zope | 2.10.5 | Yes |
| Application | zope | zope | 2.10.6 | Yes |
| Application | zope | zope | 2.10.7 | Yes |
| Application | zope | zope | 2.10.8 | Yes |
| Application | zope | zope | 2.10.9 | Yes |
| Application | zope | zope | 2.10.10 | Yes |
| Application | zope | zope | 2.10.11 | Yes |
| Application | zope | zope | 2.11.0 | Yes |
| Application | zope | zope | 2.11.0a1 | Yes |
| Application | zope | zope | 2.11.0b1 | Yes |
| Application | zope | zope | 2.11.0c1 | Yes |
| Application | zope | zope | 2.11.1 | Yes |
| Application | zope | zope | 2.11.2 | Yes |
| Application | zope | zope | 2.11.3 | Yes |
| Application | zope | zope | 2.11.4 | Yes |
| Application | zope | zope | 2.11.5 | Yes |
| Application | zope | zope | 2.12.0 | Yes |
| Application | zope | zope | 2.12.1 | Yes |
| Application | zope | zope | 2.12.2 | Yes |