Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-4650

Опубликовано: 20 фев. 2020
Источник: debian
EPSS Средний

Описание

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python2.6removedpackage
python2.6no-dsasqueezepackage
python2.6no-dsawheezypackage
python2.7fixed2.7.8-1package
python2.7no-dsawheezypackage
python3.1removedpackage
python3.1no-dsasqueezepackage
python3.2removedpackage
python3.2no-dsawheezypackage
python3.3removedpackage
python3.4fixed3.4.1-8package

Примечания

  • http://bugs.python.org/issue21766

EPSS

Процентиль: 93%
0.10304
Средний

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 5 лет назад

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.

redhat
почти 11 лет назад

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.

CVSS3: 9.8
nvd
больше 5 лет назад

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.

CVSS3: 9.8
github
около 3 лет назад

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.

fstec
почти 11 лет назад

Уязвимость программного обеспечения Python, позволяющая удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 93%
0.10304
Средний