Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2011-1015

Опубликовано: 09 мая 2011
Источник: debian
EPSS Низкий

Описание

The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python2.6fixed2.6.8-1package
python2.6no-dsawheezypackage
python2.5unfixedpackage
python2.5no-dsasqueezepackage
python2.5no-dsalennypackage
python2.4removedpackage
python2.4no-dsalennypackage

Примечания

  • Python 2.7 and 3.1 are fixed

  • http://bugs.python.org/issue2254

EPSS

Процентиль: 38%
0.00157
Низкий

Связанные уязвимости

ubuntu
около 14 лет назад

The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.

redhat
больше 17 лет назад

The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.

nvd
около 14 лет назад

The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.

github
около 3 лет назад

The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.

oracle-oval
около 14 лет назад

ELSA-2011-0554: python security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 38%
0.00157
Низкий