Zope 2.2.0 through 2.2.4 does not properly perform security registration for legacy names of object constructors such as DTML method objects, which could allow attackers to perform unauthorized activities.
http://www.zope.org/Products/Zope/Hotfix_2000-12-08/security_alert
http://www.redhat.com/support/errata/RHSA-2000-125.html
http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-083.php3