The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade python-libsUpgrade pythonUpgrade python-develUpgrade python-docsUpgrade python-toolsUpgrade tkinter | Dec 1, 2016 | May 9, 2011 |
| Gentoo Linux | — | Upgrade dev-lang/python. | Oct 30, 2017 | May 9, 2011 |
| Oracle_linux | — | Upgrade python-libsUpgrade pythonUpgrade python-docsUpgrade python-toolsUpgrade tkinterUpgrade python-testUpgrade python-devel | Oct 16, 2024 | May 9, 2011 |
| Suse | — | Upgrade python-base-x86Upgrade libpython2_6-1_0-x86Upgrade python-develUpgrade libpython2_6-1_0-32bitUpgrade python-xmlUpgrade python-base-32bitUpgrade libpython2_6-1_0Upgrade python-base | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade python2.5Upgrade python2.4-minimalUpgrade python2.6Upgrade python2.6-minimalUpgrade python2.5-minimalUpgrade python2.4 | Nov 8, 2024 | May 9, 2011 |
| Vmsa 2012 0001 | — | Upgrade VMware ESX 4.0 to build number 660575Upgrade VMware ESX 4.1 to build number 582267 | Feb 3, 2012 | May 9, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub