Описание
The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.
| Релиз | Статус | Примечание | 
|---|---|---|
| dapper | ignored  | end of life | 
| devel | DNE  | |
| hardy | released  | 2.4.5-1ubuntu4.4 | 
| lucid | DNE  | |
| maverick | DNE  | |
| natty | DNE  | |
| oneiric | DNE  | |
| precise | DNE  | |
| upstream | needs-triage  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| dapper | DNE  | |
| devel | DNE  | |
| hardy | released  | 2.5.2-2ubuntu6.2 | 
| lucid | DNE  | |
| maverick | DNE  | |
| natty | DNE  | |
| oneiric | DNE  | |
| precise | DNE  | |
| upstream | needs-triage  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| dapper | DNE  | |
| devel | DNE  | |
| hardy | DNE  | |
| lucid | released  | 2.6.5-1ubuntu6.1 | 
| maverick | ignored  | end of life | 
| natty | released  | 2.6.6-6ubuntu7.1 | 
| oneiric | released  | 2.6.7-4ubuntu1.1 | 
| precise | DNE  | |
| upstream | needs-triage  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| dapper | DNE  | |
| devel | not-affected  | |
| hardy | DNE  | |
| lucid | DNE  | |
| maverick | not-affected  | 2.7-6 | 
| natty | not-affected  | |
| oneiric | not-affected  | |
| precise | not-affected  | |
| upstream | released  | 2.7-1 | 
Показывать по
EPSS
5 Medium
CVSS2
Связанные уязвимости
The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.
The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.
The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in P ...
The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.
ELSA-2011-0554: python security, bug fix, and enhancement update (MODERATE)
EPSS
5 Medium
CVSS2