PT-2012-2008 · Python+3 · Python+3
CVSS v2.0
2.6
Baixa
| Vetor | AV:N/AC:H/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Python versions prior to 2.5.6c1
Python versions 2.6.x prior to 2.6.7 rc2
Python versions 2.7.x prior to 2.7.2
Description
The issue concerns the list directory function in Lib/SimpleHTTPServer.py in SimpleHTTPServer, which does not include a charset parameter in the Content-Type HTTP header. This omission makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks, particularly against Internet Explorer 7, by utilizing UTF-7 encoding.
Recommendations
For Python versions prior to 2.5.6c1, update to version 2.5.6c1 or later.
For Python versions 2.6.x prior to 2.6.7 rc2, update to version 2.6.7 rc2 or later.
For Python versions 2.7.x prior to 2.7.2, update to version 2.7.2 or later.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Centos
Internet Explorer
Python
Red Hat