PT-2012-2008 · Python+3 · Python+3

·

CVE-2011-4940

·

Publicado

2012-06-18

·

Atualizado

2023-02-13

CVSS v2.0

2.6

Baixa

VetorAV:N/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Python versions prior to 2.5.6c1 Python versions 2.6.x prior to 2.6.7 rc2 Python versions 2.7.x prior to 2.7.2
Description The issue concerns the list directory function in Lib/SimpleHTTPServer.py in SimpleHTTPServer, which does not include a charset parameter in the Content-Type HTTP header. This omission makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks, particularly against Internet Explorer 7, by utilizing UTF-7 encoding.
Recommendations For Python versions prior to 2.5.6c1, update to version 2.5.6c1 or later. For Python versions 2.6.x prior to 2.6.7 rc2, update to version 2.6.7 rc2 or later. For Python versions 2.7.x prior to 2.7.2, update to version 2.7.2 or later.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2012_0744
CVE-2011-4940
DLA-25-1
PSF-2012-1
RHSA-2012:0744
RHSA-2012:0745
RHSA-2012_0744
RHSA-2012_0745

Produtos afetados

Centos
Internet Explorer
Python
Red Hat