Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-76v4-rfvh-v87h

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.

The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.

EPSS

Процентиль: 38%
0.00157
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
около 14 лет назад

The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.

redhat
больше 17 лет назад

The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.

nvd
около 14 лет назад

The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.

debian
около 14 лет назад

The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in P ...

oracle-oval
около 14 лет назад

ELSA-2011-0554: python security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 38%
0.00157
Низкий

Дефекты

CWE-200