The list_directory function in Lib/SimpleHTTPServer.py in SimpleHTTPServer in Python before 2.5.6c1, 2.6.x before 2.6.7 rc2, and 2.7.x before 2.7.2 does not place a charset parameter in the Content-Type HTTP header, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks against Internet Explorer 7 via UTF-7 encoding.
CVSS Details
- CVSS 3.1 Base Score: 6.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade python | Aug 30, 2017 | Jun 27, 2012 |
| Centos_linux | — | Upgrade tkinterUpgrade pythonUpgrade python-libsUpgrade python-testUpgrade python-toolsUpgrade python-devel | Dec 1, 2016 | Jun 27, 2012 |
| Debian | — | Upgrade python2.7 | Jul 30, 2024 | Jun 27, 2012 |
| Oracle_linux | — | Upgrade python-develUpgrade python-toolsUpgrade python-libsUpgrade python-testUpgrade pythonUpgrade tkinter | Oct 16, 2024 | Jun 27, 2012 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 8, 2011 |
| Ubuntu | — | Upgrade python2.6Upgrade python2.4Upgrade python2.5Upgrade python2.7-minimalUpgrade python2.7Upgrade python2.5-minimalUpgrade python2.4-minimalUpgrade python2.6-minimal | Nov 8, 2024 | Jun 27, 2012 |
| Vmsa 2012 0016 | — | Upgrade VMware ESX 4.1 to build number 874690 | Nov 22, 2012 | Jun 27, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub