Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-1015

Опубликовано: 09 мая 2011
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 5

Описание

The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

hardy

released

2.4.5-1ubuntu4.4
lucid

DNE

maverick

DNE

natty

DNE

oneiric

DNE

precise

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

released

2.5.2-2ubuntu6.2
lucid

DNE

maverick

DNE

natty

DNE

oneiric

DNE

precise

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

DNE

lucid

released

2.6.5-1ubuntu6.1
maverick

ignored

end of life
natty

released

2.6.6-6ubuntu7.1
oneiric

released

2.6.7-4ubuntu1.1
precise

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

hardy

DNE

lucid

DNE

maverick

not-affected

2.7-6
natty

not-affected

oneiric

not-affected

precise

not-affected

upstream

released

2.7-1

Показывать по

EPSS

Процентиль: 38%
0.00157
Низкий

5 Medium

CVSS2

Связанные уязвимости

redhat
больше 17 лет назад

The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.

nvd
около 14 лет назад

The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.

debian
около 14 лет назад

The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in P ...

github
около 3 лет назад

The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.

oracle-oval
около 14 лет назад

ELSA-2011-0554: python security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 38%
0.00157
Низкий

5 Medium

CVSS2