Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-7235

Опубликовано: 23 мар. 2017
Источник: nvd
CVSS3: 8.8
CVSS2: 6.8
EPSS Низкий

Описание

An issue was discovered in cloudflare-scrape 1.6.6 through 1.7.1. A malicious website owner could craft a page that executes arbitrary Python code against any cfscrape user who scrapes that website. This is fixed in 1.8.0.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cloudflare-scrape_project:cloudflare-scrape:1.6.6:*:*:*:*:*:*:*
cpe:2.3:a:cloudflare-scrape_project:cloudflare-scrape:1.6.7:*:*:*:*:*:*:*
cpe:2.3:a:cloudflare-scrape_project:cloudflare-scrape:1.6.8:*:*:*:*:*:*:*
cpe:2.3:a:cloudflare-scrape_project:cloudflare-scrape:1.7.0:*:*:*:*:*:*:*
cpe:2.3:a:cloudflare-scrape_project:cloudflare-scrape:1.7.1:*:*:*:*:*:*:*

EPSS

Процентиль: 65%
0.00494
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 8.8
github
больше 7 лет назад

cfscrape Improper Input Validation vulnerability

EPSS

Процентиль: 65%
0.00494
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-20