CVE-2005-0088
published 2005-05-02CVE-2005-0088: The publisher handler for mod_python 2.7.8 and earlier allows remote attackers to obtain access to restricted objects via a crafted URL.
PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
6.46%
93.0th percentile
The publisher handler for mod_python 2.7.8 and earlier allows remote attackers to obtain access to restricted objects via a crafted URL.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | mod_python | <= 2.7.8 | — |
| apache | mod_python | — | — |
| apache | mod_python | — | — |
| apache | mod_python | — | — |
| apache | mod_python | — | — |
| apache | mod_python | — | — |
| apache | mod_python | — | — |
| apache | mod_python | — | — |
| apache | mod_python | — | — |
| apache | mod_python | — | — |
| apache | mod_python | — | — |
| apache | mod_python | — | — |
| apache | mod_python | — | — |
| apache | mod_python | — | — |
| apache | mod_python | — | — |
| apache | mod_python | — | — |
| apache | mod_python | — | — |
| apache | mod_python | — | — |
| apache | mod_python | — | — |
| apache | mod_python | — | — |
| apache | mod_python | — | — |
| apache | mod_python | — | — |
| debian | libapache2-mod-python | < libapache2-mod-python 3.1.3-3 (bookworm) | libapache2-mod-python 3.1.3-3 (bookworm) |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
mod_python vulnerability
vendor_ubuntu·2005-02-11
CVE-2005-0088 mod_python vulnerability
Title: mod_python vulnerability
Summary: mod_python vulnerability
Graham Dumpleton discovered an information disclosure in the
"publisher" handle of mod_python. By requesting a carefully crafted
URL for a published module page, anybody can obtain extra information
about internal variables, objects, and other information which is not
intended to be visible.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
security flaw
vendor_redhat·2005-02-10·CVSS 7.5
CVE-2005-0088 [HIGH] security flaw
security flaw
The publisher handler for mod_python 2.7.8 and earlier allows remote attackers to obtain access to restricted objects via a crafted URL.
Debian
CVE-2005-0088: libapache2-mod-python - The publisher handler for mod_python 2.7.8 and earlier allows remote attackers t...
vendor_debian·2005·CVSS 7.5
CVE-2005-0088 [HIGH] CVE-2005-0088: libapache2-mod-python - The publisher handler for mod_python 2.7.8 and earlier allows remote attackers t...
The publisher handler for mod_python 2.7.8 and earlier allows remote attackers to obtain access to restricted objects via a crafted URL.
Scope: local
bookworm: resolved (fixed in 3.1.3-3)
bullseye: resolved (fixed in 3.1.3-3)
forky: resolved (fixed in 3.1.3-3)
sid: resolved (fixed in 3.1.3-3)
GHSA
GHSA-4xhm-pcpf-389c: The publisher handler for mod_python 2
ghsa_unreviewed·2022-05-01
CVE-2005-0088 [HIGH] GHSA-4xhm-pcpf-389c: The publisher handler for mod_python 2
The publisher handler for mod_python 2.7.8 and earlier allows remote attackers to obtain access to restricted objects via a crafted URL.
OSV
CVE-2005-0088: The publisher handler for mod_python 2
osv·2005-05-02·CVSS 7.5
CVE-2005-0088 [HIGH] CVE-2005-0088: The publisher handler for mod_python 2
The publisher handler for mod_python 2.7.8 and earlier allows remote attackers to obtain access to restricted objects via a crafted URL.
No detection rules found.
No public exploits indexed.
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000926http://marc.info/?l=bugtraq&m=110815313218389&w=2http://security.gentoo.org/glsa/glsa-200502-14.xmlhttp://securitytracker.com/id?1013156http://www.debian.org/security/2005/dsa-689http://www.kb.cert.org/vuls/id/356409http://www.redhat.com/support/errata/RHSA-2005-100.htmlhttp://www.redhat.com/support/errata/RHSA-2005-104.htmlhttp://www.securityfocus.com/archive/1/430286/100/0/threadedhttp://www.securityfocus.com/bid/12519http://www.trustix.org/errata/2005/0003/https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10617http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000926http://marc.info/?l=bugtraq&m=110815313218389&w=2http://security.gentoo.org/glsa/glsa-200502-14.xmlhttp://securitytracker.com/id?1013156http://www.debian.org/security/2005/dsa-689http://www.kb.cert.org/vuls/id/356409http://www.redhat.com/support/errata/RHSA-2005-100.htmlhttp://www.redhat.com/support/errata/RHSA-2005-104.htmlhttp://www.securityfocus.com/archive/1/430286/100/0/threadedhttp://www.securityfocus.com/bid/12519http://www.trustix.org/errata/2005/0003/https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10617
2005-05-02
Published