Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-1015

Опубликовано: 09 мая 2011
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:python:python:3.0:*:*:*:*:*:*:*

EPSS

Процентиль: 38%
0.00157
Низкий

5 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

ubuntu
около 14 лет назад

The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.

redhat
больше 17 лет назад

The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.

debian
около 14 лет назад

The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in P ...

github
около 3 лет назад

The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.

oracle-oval
около 14 лет назад

ELSA-2011-0554: python security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 38%
0.00157
Низкий

5 Medium

CVSS2

Дефекты

CWE-200