[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248678

 
 

909

 
 

195426

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2011-4940Date: (C)2012-06-27   (M)2024-04-19


The list_directory function in Lib/SimpleHTTPServer.py in SimpleHTTPServer in Python before 2.5.6c1, 2.6.x before 2.6.7 rc2, and 2.7.x before 2.7.2 does not place a charset parameter in the Content-Type HTTP header, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks against Internet Explorer 7 via UTF-7 encoding.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 2.6
Exploit Score: 4.9
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: HIGH
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
SECUNIA-50858
SECUNIA-51024
SECUNIA-51040
BID-54083
JVN#51176027
JVNDB-2012-000063
USN-1592-1
USN-1596-1
USN-1613-1
USN-1613-2
http://bugs.python.org/issue11442
https://bugzilla.redhat.com/show_bug.cgi?id=803500

CWE    1
CWE-79
OVAL    13
oval:org.secpod.oval:def:17189
oval:org.secpod.oval:def:701030
oval:org.secpod.oval:def:1300085
oval:org.secpod.oval:def:1601304
...

© SecPod Technologies