File contents
Hotfix_06_16_2000
This is a "hotfix" product. Hotfix products can be installed to
incorporate modifications to Zope at runtime without requiring
an immediate installation upgrade. Hotfix products are installed
just as you would install any other Zope product.
This hotfix addresses an important security issue that affects all
released Zope versions up to and including Zope 2.2.0 beta 1.
The issue involves an inadequately protected method in one of the
base classes in the DocumentTemplate package that could allow the
contents of DTMLDocuments or DTMLMethods to be changed remotely or
through DTML code without forcing proper user authorization.
While we know of no instances of this issue being used to exploit a
site, we *highly* recommend that any Zope site that is accessible by
untrusted clients have this hotfix product installed to mitigate the
issue.