Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-4650

Опубликовано: 20 фев. 2020
Источник: debian
EPSS Низкий

Описание

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python2.6removedpackage
python2.6no-dsasqueezepackage
python2.6no-dsawheezypackage
python2.7fixed2.7.8-1package
python2.7no-dsawheezypackage
python3.1removedpackage
python3.1no-dsasqueezepackage
python3.2removedpackage
python3.2no-dsawheezypackage
python3.3removedpackage
python3.4fixed3.4.1-8package

Примечания

  • http://bugs.python.org/issue21766

EPSS

Процентиль: 91%
0.06019
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 6 лет назад

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.

redhat
почти 12 лет назад

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.

CVSS3: 9.8
nvd
около 6 лет назад

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.

CVSS3: 9.8
github
почти 4 года назад

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.

fstec
больше 11 лет назад

Уязвимость программного обеспечения Python, позволяющая удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 91%
0.06019
Низкий