Описание
The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.
Релиз | Статус | Примечание |
---|---|---|
dapper | ignored | end of life |
devel | DNE | |
hardy | released | 2.4.5-1ubuntu4.4 |
lucid | DNE | |
maverick | DNE | |
natty | DNE | |
oneiric | DNE | |
precise | DNE | |
upstream | needs-triage |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
dapper | DNE | |
devel | DNE | |
hardy | released | 2.5.2-2ubuntu6.2 |
lucid | DNE | |
maverick | DNE | |
natty | DNE | |
oneiric | DNE | |
precise | DNE | |
upstream | needs-triage |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
dapper | DNE | |
devel | DNE | |
hardy | DNE | |
lucid | released | 2.6.5-1ubuntu6.1 |
maverick | ignored | end of life |
natty | released | 2.6.6-6ubuntu7.1 |
oneiric | released | 2.6.7-4ubuntu1.1 |
precise | DNE | |
upstream | needs-triage |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
dapper | DNE | |
devel | not-affected | |
hardy | DNE | |
lucid | DNE | |
maverick | not-affected | 2.7-6 |
natty | not-affected | |
oneiric | not-affected | |
precise | not-affected | |
upstream | released | 2.7-1 |
Показывать по
EPSS
5 Medium
CVSS2
Связанные уязвимости
The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.
The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.
The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in P ...
The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.
ELSA-2011-0554: python security, bug fix, and enhancement update (MODERATE)
EPSS
5 Medium
CVSS2